Re: [blfs-book] [BLFS Trac] #8302: php-7.0.11 (CVE-2016-7412 CVE-2016-7413 CVE-2016-7414 CVE-2016-7415 CVE-2016-7416 CVE-2016-7417 CVE-2016-7418)

2016-09-16 Thread BLFS Trac via blfs-book
#8302: php-7.0.11 (CVE-2016-7412 CVE-2016-7413 CVE-2016-7414 CVE-2016-7415
CVE-2016-7416 CVE-2016-7417 CVE-2016-7418)
-+-
 Reporter:  bdubbs@… |   Owner:  renodr
 Type:  enhancement  |  Status:  closed
 Priority:  highest  |   Milestone:  7.11
Component:  BOOK | Version:  SVN
 Severity:  normal   |  Resolution:  fixed
 Keywords:   |
-+-
Changes (by renodr):

 * status:  assigned => closed
 * resolution:   => fixed


Comment:

 Fixed at r17770

--
Ticket URL: 
BLFS Trac 
Beyond Linux From Scratch
-- 
http://lists.linuxfromscratch.org/listinfo/blfs-book
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page

Re: [blfs-book] [BLFS Trac] #8302: php-7.0.11 (CVE-2016-7412 CVE-2016-7413 CVE-2016-7414 CVE-2016-7415 CVE-2016-7416 CVE-2016-7417 CVE-2016-7418) (was: php-7.0.11)

2016-09-16 Thread BLFS Trac via blfs-book
#8302: php-7.0.11 (CVE-2016-7412 CVE-2016-7413 CVE-2016-7414 CVE-2016-7415
CVE-2016-7416 CVE-2016-7417 CVE-2016-7418)
-+---
 Reporter:  bdubbs@… |   Owner:  renodr
 Type:  enhancement  |  Status:  assigned
 Priority:  highest  |   Milestone:  7.11
Component:  BOOK | Version:  SVN
 Severity:  normal   |  Resolution:
 Keywords:   |
-+---

Comment (by renodr):

 Updated title with CVE numbers.

 CVE-2016-7412: Heap overflow in mysqlnd related to BIT fields
 CVE-2016-7413: wddx_deserialize use-after-free
 CVE-2016-7414: Out of bounds r/w when verifying signature of zip phar in
 phar_parse_zipfile
 CVE-2016-7415: ICU: add locale length check
 CVE-2016-7416: PHP/ICU: add locale length check
 CVE-2016-7417: Missing type check when unserializing SplArray
 CVE-2016-7418: Out-Of-Bounds read in php_wddx_push_element

 I'll give links tomorrow.

--
Ticket URL: 
BLFS Trac 
Beyond Linux From Scratch
-- 
http://lists.linuxfromscratch.org/listinfo/blfs-book
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page