You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa php

Sigurnosni nedostaci programskog paketa php

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

Fedora Update Notification
2016-05-29 17:44:54.114245

Name : php
Product : Fedora 23
Version : 5.6.22
Release : 1.fc23
Summary : PHP scripting language for creating dynamic web sites
Description :
PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated web pages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts.

The php package contains the module (often referred to as mod_php)
which adds support for the PHP language to Apache HTTP Server.

Update Information:

26 May 2016, **PHP 5.6.22** **Core:** * Fixed bug #72172 (zend_hex_strtod
should not use strlen). (bwitz at hotmail dot com ) * Fixed bug #72114 (Integer
underflow / arbitrary null write in fread/gzread). (Stas) * Fixed bug #72135
(Integer Overflow in php_html_entities). (Stas) **GD:** * Fixed bug #72227
(imagescale out-of-bounds read). (Stas) **Intl:** * Fixed bug #64524 (Add
intl.use_exceptions to php.ini-*). (Anatol) * Fixed bug #72241
(get_icu_value_internal out-of-bounds read). (Stas) **Postgres:** * Fixed bug
#72151 (mysqli_fetch_object changed behaviour). (Anatol)

[ 1 ] Bug #1339949 – CVE-2016-5096 php: Integer underflow causing arbitrary null write in fread/gzread
[ 2 ] Bug #1339590 – CVE-2016-5093 php: Out-of-bounds heap read in get_icu_value_internal

This update can be installed with the “yum” update program. Use
su -c ‘yum update php’ at the command line.
For more information, refer to “Managing Software with yum”,
available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list

AutorMarko Stanec
Cert idNCERT-REF-2016-05-0005-ADV
More in Preporuke
Sigurnosni nedostaci programskog paketa webkitgtk4

Otkriveni su sigurnosni nedostaci u programskom paketu webkitgtk4 za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju izvršavanje proizvoljnog programskog...