First published: Wed May 22 2019(Updated: )
USN-3566-1 fixed several vulnerabilities in PHP. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. It was discovered that PHP incorrectly handled certain files. An attacker could possibly use this issue to access sensitive information. (CVE-2018-20783) It was discovered that PHP incorrectly handled certain files. An attacker could possibly use this issue to access sensitive information or possibly cause a crash, resulting in a denial of service. (CVE-2019-11036) Original advisory details: It was discovered that PHP incorrectly handled memory when unserializing certain data. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 12.04 ESM. (CVE-2017-12933) It was discovered that PHP incorrectly handled locale length. A remote attacker could possibly use this issue to cause PHP to crash, resulting in a denial of service. This issue only affected Ubuntu 12.04 ESM. (CVE-2017-11362) It was discovered that PHP incorrectly handled certain stream metadata. A remote attacker could possibly use this issue to set arbitrary metadata. This issue only affected Ubuntu 12.04 ESM. (CVE-2016-10712)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libapache2-mod-php5 | <5.5.9+dfsg-1ubuntu4.29+esm2 | 5.5.9+dfsg-1ubuntu4.29+esm2 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/php5-fpm | <5.5.9+dfsg-1ubuntu4.29+esm2 | 5.5.9+dfsg-1ubuntu4.29+esm2 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/php5-cgi | <5.5.9+dfsg-1ubuntu4.29+esm2 | 5.5.9+dfsg-1ubuntu4.29+esm2 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/php5-cli | <5.5.9+dfsg-1ubuntu4.29+esm2 | 5.5.9+dfsg-1ubuntu4.29+esm2 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/libapache2-mod-php5 | <5.3.10-1ubuntu3.36 | 5.3.10-1ubuntu3.36 |
Ubuntu OpenSSH Client | =12.04 | |
All of | ||
ubuntu/php5-fpm | <5.3.10-1ubuntu3.36 | 5.3.10-1ubuntu3.36 |
Ubuntu OpenSSH Client | =12.04 | |
All of | ||
ubuntu/php5-cgi | <5.3.10-1ubuntu3.36 | 5.3.10-1ubuntu3.36 |
Ubuntu OpenSSH Client | =12.04 | |
All of | ||
ubuntu/php5-cli | <5.3.10-1ubuntu3.36 | 5.3.10-1ubuntu3.36 |
Ubuntu OpenSSH Client | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
USN-3566-2 fixed several vulnerabilities in PHP.
The CVE ID for the PHP vulnerabilities fixed by USN-3566-2 is CVE-2018-20783.
USN-3566-2 affects Ubuntu 14.04 and Ubuntu 12.04 ESM.
The remedy for the PHP vulnerabilities in Ubuntu 14.04 is to update the packages libapache2-mod-php5, php5-fpm, php5-cgi, and php5-cli to version 5.5.9+dfsg-1ubuntu4.29+esm2.
The remedy for the PHP vulnerabilities in Ubuntu 12.04 ESM is to update the packages libapache2-mod-php5, php5-fpm, php5-cgi, and php5-cli to version 5.3.10-1ubuntu3.36.