[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1970-1] php5 security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : php5
Version        : 5.6.40+dfsg-0+deb8u7
CVE ID         : CVE-2019-11043


Emil Lerner, beched and d90pwn found a buffer underflow in php5-fpm, a
Fast Process Manager for the PHP language, which can lead to remote
code execution.

Instances are vulnerable depending on the web server configuration, in
particular PATH_INFO handling.  For a full list of preconditions,
check: https://github.com/neex/phuip-fpizdam

For Debian 8 "Jessie", this problem has been fixed in version
5.6.40+dfsg-0+deb8u7.

We recommend that you upgrade your php5 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEEQic8GuN/xDR88HkSj/HLbo2JBZ8FAl20YgEACgkQj/HLbo2J
BZ8u3ggAgHB+rJVnpGssmR85aY34EuMptcQUKkRt1s+rkuR5eBpk7JNtu6Pnp+z4
o1gOEQ8Z+0trRc2ydQu6BbTwXjZ1kLTZrg7E2zuGU7Lywnk3LihdMDljIKS8Yzi/
9mOrh0QqHfydiaiH1QjlaMWAdRlqYq//PwNID8UoK+CEgvY9Jk/uWMemEX/0YBZU
Fpb2miVy+R123bh5Y+P3TT+LcijlTPq4ZU7CDnz7oyRxfSubossU1eFpF6ok4iZh
WB323BjNaf3E3OrmIyMXpMh8z6QV2G8eLG2a6ZZ1T3MSmpx2cq+lV+sg0PosiSZA
27B4PkxM7muLw49jq04DIrM1/+BWpA==
=SuP9
-----END PGP SIGNATURE-----


Reply to: