First published: Fri Nov 01 2019(Updated: )
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.<br>The following packages have been upgraded to a later upstream version: rh-php72-php (7.2.24). (BZ#1766603)<br>Security Fix(es):<br><li> php: underflow in env_path_info in fpm_main.c (CVE-2019-11043)</li> <li> gd: Unsigned integer underflow _gdContributionsAlloc() (CVE-2016-10166)</li> <li> gd: Heap based buffer overflow in gdImageColorMatch() in gd_color_match.c (CVE-2019-6977)</li> <li> php: Invalid memory access in function xmlrpc_decode() (CVE-2019-9020)</li> <li> php: File rename across filesystems may allow unwanted access during processing (CVE-2019-9637)</li> <li> php: Uninitialized read in exif_process_IFD_in_MAKERNOTE (CVE-2019-9638)</li> <li> php: Uninitialized read in exif_process_IFD_in_MAKERNOTE (CVE-2019-9639)</li> <li> php: Invalid read in exif_process_SOFn() (CVE-2019-9640)</li> <li> php: Out-of-bounds read due to integer overflow in iconv_mime_decode_headers() (CVE-2019-11039)</li> <li> php: Buffer over-read in exif_read_data() (CVE-2019-11040)</li> <li> php: Buffer over-read in PHAR reading functions (CVE-2018-20783)</li> <li> php: Heap-based buffer over-read in PHAR reading functions (CVE-2019-9021)</li> <li> php: memcpy with negative length via crafted DNS response (CVE-2019-9022)</li> <li> php: Heap-based buffer over-read in mbstring regular expression functions (CVE-2019-9023)</li> <li> php: Out-of-bounds read in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c (CVE-2019-9024)</li> <li> php: Heap buffer overflow in function exif_process_IFD_TAG() (CVE-2019-11034)</li> <li> php: Heap buffer overflow in function exif_iif_add_value() (CVE-2019-11035)</li> <li> php: Buffer over-read in exif_process_IFD_TAG() leading to information disclosure (CVE-2019-11036)</li> <li> gd: Information disclosure in gdImageCreateFromXbm() (CVE-2019-11038)</li> <li> php: heap buffer over-read in exif_scan_thumbnail() (CVE-2019-11041)</li> <li> php: heap buffer over-read in exif_process_user_comment() (CVE-2019-11042)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-php72-php | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-bcmath | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-cli | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-common | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-dba | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-debuginfo | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-devel | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-embedded | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-enchant | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-fpm | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-gd | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-gmp | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-intl | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-json | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-ldap | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-mbstring | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-mysqlnd | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-odbc | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-opcache | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-pdo | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-pgsql | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-process | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-pspell | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-recode | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-snmp | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-soap | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-xml | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-xmlrpc | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-zip | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-bcmath | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-cli | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-common | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-dba | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-debuginfo | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-devel | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-embedded | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-enchant | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-fpm | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-gd | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-gmp | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-intl | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-json | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-ldap | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-mbstring | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-mysqlnd | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-odbc | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-opcache | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-pdo | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-pgsql | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-process | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-pspell | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-recode | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-snmp | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-soap | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-xml | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-xmlrpc | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-zip | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-bcmath | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-cli | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-common | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-dba | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-debuginfo | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-devel | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-embedded | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-enchant | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-fpm | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-gd | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-gmp | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-intl | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-json | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-ldap | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-mbstring | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-mysqlnd | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-odbc | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-opcache | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-pdo | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-pgsql | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-process | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-pspell | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-recode | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-snmp | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-soap | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-xml | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-xmlrpc | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php-zip | <7.2.24-1.el7 | 7.2.24-1.el7 |
redhat/rh-php72-php | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-bcmath | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-cli | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-common | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-dba | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-debuginfo | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-devel | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-embedded | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-enchant | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-fpm | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-gd | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-gmp | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-intl | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-json | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-ldap | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-mbstring | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-mysqlnd | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-odbc | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-opcache | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-pdo | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-pgsql | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-process | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-pspell | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-recode | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-snmp | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-soap | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-xml | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-xmlrpc | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
redhat/rh-php72-php-zip | <7.2.24-1.el7.aa | 7.2.24-1.el7.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.