RHSA-2018:1296: Moderate: rh-php70-php security, bug fix, and enhancement update

Published May 3, 2018
·
Updated

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.<br>The following packages have been upgraded to a later upstream version: rh-php70-php (7.0.27). (BZ#1518843)<br>Security Fix(es):<br><li> php: Heap overflow in mysqlnd when not receiving UNSIGNEDFLAG in BIT field (CVE-2016-7412)</li> <li> php: Use after free in wddxdeserialize (CVE-2016-7413)</li> <li> php: Out of bounds heap read when verifying signature of zip phar in pharparsezipfile (CVE-2016-7414)</li> <li> php: Stack based buffer overflow in msgfmtformatmessage (CVE-2016-7416)</li> <li> php: Missing type check when unserializing SplArray (CVE-2016-7417)</li> <li> php: Null pointer dereference in phpwddxpushelement (CVE-2016-7418)</li> <li> php: Use-after-free vulnerability when resizing the 'properties' hash table of a serialized object (CVE-2016-7479)</li> <li> php: Invalid read when wddx decodes empty boolean element (CVE-2016-9935)</li> <li> php: Use After Free in unserialize() (CVE-2016-9936)</li> <li> php: Wrong calculation in exifconvertanytoint function (CVE-2016-10158)</li> <li> php: Integer overflow in pharparsepharfile (CVE-2016-10159)</li> <li> php: Off-by-one error in pharparsepharfile when loading crafted phar archive (CVE-2016-10160)</li> <li> php: Out-of-bounds heap read on unserialize in finishnesteddata() (CVE-2016-10161)</li> <li> php: Null pointer dereference when unserializing PHP object (CVE-2016-10162)</li> <li> gd: DoS vulnerability in gdImageCreateFromGd2Ctx() (CVE-2016-10167)</li> <li> gd: Integer overflow in gdio.c (CVE-2016-10168)</li> <li> php: Use of uninitialized memory in unserialize() (CVE-2017-5340)</li> <li> php: Buffer over-read from unitialized data in gdImageCreateFromGifCtx function (CVE-2017-7890)</li> <li> oniguruma: Out-of-bounds stack read in matchat() during regular expression searching (CVE-2017-9224)</li> <li> oniguruma: Heap buffer overflow in nextstateval() during regular expression compilation (CVE-2017-9226)</li> <li> oniguruma: Out-of-bounds stack read in mbcenclen() during regular expression searching (CVE-2017-9227)</li> <li> oniguruma: Out-of-bounds heap write in bitsetsetrange() (CVE-2017-9228)</li> <li> oniguruma: Invalid pointer dereference in leftadjustcharhead() (CVE-2017-9229)</li> <li> php: Incorrect WDDX deserialization of boolean parameters leads to DoS (CVE-2017-11143)</li> <li> php: Incorrect return value check of OpenSSL sealing function leads to crash (CVE-2017-11144)</li> <li> php: Out-of-bounds read in pharparsepharfile (CVE-2017-11147)</li> <li> php: Stack-based buffer over-read in msgfmtparsemessage function (CVE-2017-11362)</li> <li> php: Stack based 1-byte buffer over-write in zendinidoop() function Zend/zendiniparser.c (CVE-2017-11628)</li> <li> php: heap use after free in ext/standard/varunserializer.re (CVE-2017-12932)</li> <li> php: heap use after free in ext/standard/varunserializer.re (CVE-2017-12934)</li> <li> php: reflected XSS in .phar 404 page (CVE-2018-5712)</li> <li> php, gd: Stack overflow in gdImageFillToBorder on truecolor images (CVE-2016-9933)</li> <li> php: NULL Pointer Dereference in WDDX Packet Deserialization with PDORow (CVE-2016-9934)</li> <li> php: wddxdeserialize() heap out-of-bound read via phpparsedate() (CVE-2017-11145)</li> <li> php: buffer over-read in finishnesteddata function (CVE-2017-12933)</li> <li> php: Out-of-bound read in timelibmeridian() (CVE-2017-16642)</li> <li> php: Denial of Service (DoS) via infinite loop in libgd gdImageCreateFromGifCtx function in ext/gd/libgd/gdgifin.c (CVE-2018-5711)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For details, see the Red Hat Software Collections 3.1 Release Notes linked from the References section.

Affected Software

64 affected componentsFixes available
redhat/rh-php70-php<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-bcmath<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-cli<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-common<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-dba<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-dbg<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-debuginfo<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-devel<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-embedded<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-enchant<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-fpm<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-gd<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-gmp<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-intl<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-json<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-ldap<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-mbstring<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-mysqlnd<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-odbc<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-opcache<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-pdo<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-pgsql<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-process<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-pspell<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-recode<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-snmp<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-soap<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-xml<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-xmlrpc<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php-zip<7.0.27-1.el7
7.0.27-1.el7
redhat/rh-php70-php<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-bcmath<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-cli<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-common<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-dba<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-dbg<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-debuginfo<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-devel<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-embedded<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-enchant<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-fpm<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-gd<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-gmp<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-imap<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-intl<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-json<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-ldap<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-mbstring<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-mysqlnd<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-odbc<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-opcache<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-pdo<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-pgsql<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-process<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-pspell<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-recode<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-snmp<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-soap<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-tidy<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-xml<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-xmlrpc<7.0.27-1.el6
7.0.27-1.el6
redhat/rh-php70-php-zip<7.0.27-1.el6
7.0.27-1.el6

Remediation

Event History

Nov 3, 2024
Advisory Published
via Red Hat·12:55 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2018:1296?

The severity of RHSA-2018:1296 is classified as moderate.

2

How do I fix RHSA-2018:1296?

To fix RHSA-2018:1296, upgrade the affected packages to version 7.0.27-1.el7.

3

What specific vulnerabilities are addressed by RHSA-2018:1296?

RHSA-2018:1296 addresses a heap overflow vulnerability in mysqlnd.

4

Which PHP packages are affected by RHSA-2018:1296?

The affected PHP packages include rh-php70-php, rh-php70-php-bcmath, and many others listed in the advisory.

5

What is the recommended action in response to RHSA-2018:1296?

The recommended action is to apply the provided security updates as soon as possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203