First published: Mon May 14 2018(Updated: )
It was discovered that PHP incorrectly handled opcache access controls when configured to use PHP-FPM. A local user could possibly use this issue to obtain sensitive information from another user's PHP applications. (CVE-2018-10545) It was discovered that the PHP iconv stream filter incorrect handled certain invalid multibyte sequences. A remote attacker could possibly use this issue to cause PHP to hang, resulting in a denial of service. (CVE-2018-10546) It was discovered that the PHP PHAR error pages incorrectly filtered certain data. A remote attacker could possibly use this issue to perform a reflected XSS attack. (CVE-2018-10547) It was discovered that PHP incorrectly handled LDAP. A malicious remote LDAP server could possibly use this issue to cause PHP to crash, resulting in a denial of service. (CVE-2018-10548) It was discovered that PHP incorrectly handled certain exif tags in JPEG images. A remote attacker could possibly use this issue to cause PHP to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 17.10, and Ubuntu 18.04 LTS. (CVE-2018-10549)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libapache2-mod-php7.2 | <7.2.5-0ubuntu0.18.04.1 | 7.2.5-0ubuntu0.18.04.1 |
=18.04 | ||
All of | ||
ubuntu/php7.2-cgi | <7.2.5-0ubuntu0.18.04.1 | 7.2.5-0ubuntu0.18.04.1 |
=18.04 | ||
All of | ||
ubuntu/php7.2-cli | <7.2.5-0ubuntu0.18.04.1 | 7.2.5-0ubuntu0.18.04.1 |
=18.04 | ||
All of | ||
ubuntu/php7.2-fpm | <7.2.5-0ubuntu0.18.04.1 | 7.2.5-0ubuntu0.18.04.1 |
=18.04 | ||
All of | ||
ubuntu/libapache2-mod-php7.1 | <7.1.17-0ubuntu0.17.10.1 | 7.1.17-0ubuntu0.17.10.1 |
=17.10 | ||
All of | ||
ubuntu/php7.1-cgi | <7.1.17-0ubuntu0.17.10.1 | 7.1.17-0ubuntu0.17.10.1 |
=17.10 | ||
All of | ||
ubuntu/php7.1-cli | <7.1.17-0ubuntu0.17.10.1 | 7.1.17-0ubuntu0.17.10.1 |
=17.10 | ||
All of | ||
ubuntu/php7.1-fpm | <7.1.17-0ubuntu0.17.10.1 | 7.1.17-0ubuntu0.17.10.1 |
=17.10 | ||
All of | ||
ubuntu/libapache2-mod-php7.0 | <7.0.30-0ubuntu0.16.04.1 | 7.0.30-0ubuntu0.16.04.1 |
=16.04 | ||
All of | ||
ubuntu/php7.0-cgi | <7.0.30-0ubuntu0.16.04.1 | 7.0.30-0ubuntu0.16.04.1 |
=16.04 | ||
All of | ||
ubuntu/php7.0-cli | <7.0.30-0ubuntu0.16.04.1 | 7.0.30-0ubuntu0.16.04.1 |
=16.04 | ||
All of | ||
ubuntu/php7.0-fpm | <7.0.30-0ubuntu0.16.04.1 | 7.0.30-0ubuntu0.16.04.1 |
=16.04 | ||
All of | ||
ubuntu/libapache2-mod-php5 | <5.5.9+dfsg-1ubuntu4.25 | 5.5.9+dfsg-1ubuntu4.25 |
=14.04 | ||
All of | ||
ubuntu/php5-cgi | <5.5.9+dfsg-1ubuntu4.25 | 5.5.9+dfsg-1ubuntu4.25 |
=14.04 | ||
All of | ||
ubuntu/php5-cli | <5.5.9+dfsg-1ubuntu4.25 | 5.5.9+dfsg-1ubuntu4.25 |
=14.04 | ||
All of | ||
ubuntu/php5-fpm | <5.5.9+dfsg-1ubuntu4.25 | 5.5.9+dfsg-1ubuntu4.25 |
=14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)