Debian Security Advisory
DLA-1970-1 php5 -- LTS security update
- Date Reported:
- 26 Oct 2019
- Affected Packages:
- php5
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2019-11043.
- More information:
-
Emil Lerner, beched and d90pwn found a buffer underflow in php5-fpm, a Fast Process Manager for the PHP language, which can lead to remote code execution.
Instances are vulnerable depending on the web server configuration, in particular PATH_INFO handling. For a full list of preconditions, check: https://github.com/neex/phuip-fpizdam
For Debian 8
Jessie
, this problem has been fixed in version 5.6.40+dfsg-0+deb8u7.We recommend that you upgrade your php5 packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS