[El-errata] ELSA-2015-1219 Moderate: Oracle Linux Software Collections 1.2 for Oracle Linux 6 php54-php security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Fri Feb 5 13:50:40 PST 2016


Oracle Linux Software Collections Security Advisory ELSA-2015-1219

The following updated rpms for Oracle Linux Software Collections 1.2 for 
Oracle Linux 6 have been uploaded to the Unbreakable Linux Network:

x86_64:
php54-php-5.4.40-3.el6.x86_64.rpm
php54-php-bcmath-5.4.40-3.el6.x86_64.rpm
php54-php-cli-5.4.40-3.el6.x86_64.rpm
php54-php-common-5.4.40-3.el6.x86_64.rpm
php54-php-dba-5.4.40-3.el6.x86_64.rpm
php54-php-devel-5.4.40-3.el6.x86_64.rpm
php54-php-enchant-5.4.40-3.el6.x86_64.rpm
php54-php-fpm-5.4.40-3.el6.x86_64.rpm
php54-php-gd-5.4.40-3.el6.x86_64.rpm
php54-php-imap-5.4.40-3.el6.x86_64.rpm
php54-php-intl-5.4.40-3.el6.x86_64.rpm
php54-php-ldap-5.4.40-3.el6.x86_64.rpm
php54-php-mbstring-5.4.40-3.el6.x86_64.rpm
php54-php-mysqlnd-5.4.40-3.el6.x86_64.rpm
php54-php-odbc-5.4.40-3.el6.x86_64.rpm
php54-php-pdo-5.4.40-3.el6.x86_64.rpm
php54-php-pgsql-5.4.40-3.el6.x86_64.rpm
php54-php-process-5.4.40-3.el6.x86_64.rpm
php54-php-pspell-5.4.40-3.el6.x86_64.rpm
php54-php-recode-5.4.40-3.el6.x86_64.rpm
php54-php-snmp-5.4.40-3.el6.x86_64.rpm
php54-php-soap-5.4.40-3.el6.x86_64.rpm
php54-php-tidy-5.4.40-3.el6.x86_64.rpm
php54-php-xml-5.4.40-3.el6.x86_64.rpm
php54-php-xmlrpc-5.4.40-3.el6.x86_64.rpm


SRPMS:
http://oss.oracle.com/SCL/1.2/OL6/SRPMS/php54-php-5.4.40-3.el6.src.rpm



Description of changes:

[5.4.40-3]
- fix more functions accept paths with NUL character #1213407

[5.4.40-2]
- core: fix multipart/form-data request can use excessive
   amount of CPU usage CVE-2015-4024
- fix various functions accept paths with NUL character
   CVE-2015-4025, CVE-2015-4026
- ftp: fix integer overflow leading to heap overflow when
   reading FTP file listing CVE-2015-4022
- phar: fix memory corruption in phar_parse_tarfile caused by
   empty entry file name CVE-2015-4021
- pgsql: fix NULL pointer dereference CVE-2015-1352




More information about the El-errata mailing list