diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 47d0a4e41da0..8361eff264e8 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,46 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + PHP -- multiple vulnerabilities + + + php56 + 5.6.26 + + + + +

PHP reports:

+
+
    +
  • Fixed bug #73007 (add locale length check)

  • +
  • Fixed bug #72293 (Heap overflow in mysqlnd related to BIT fields)

  • +
  • Fixed bug #72928 (Out of bound when verify signature of zip phar in phar_parse_zipfile)

  • +
  • Fixed bug #73029 (Missing type check when unserializing SplArray)

  • +
  • Fixed bug #73052 (Memory Corruption in During Deserialized-object Destruction)

  • +
  • Fixed bug #72860 (wddx_deserialize use-after-free)

  • +
  • Fixed bug #73065 (Out-Of-Bounds Read in php_wddx_push_element)

  • +
+
+ +
+ + http://php.net/ChangeLog-5.php#5.6.26 + CVE-2016-7416 + CVE-2016-7412 + CVE-2016-7414 + CVE-2016-7417 + CVE-2016-7411 + CVE-2016-7413 + CVE-2016-7418 + + + 2016-09-16 + 2016-09-30 + +
+ file-roller -- path traversal vulnerability