2019年4月30日 星期二

[USN-3922-2] PHP vulnerabilities

---------- Forwarded message ---------
From: Leonidas S. Barbosa
Date: Apr 23, 2019 10:42PM

USN-3922-1 fixed vulnerabilities in PHP. This update provides the
corresponding update for Ubuntu 14.04 LTS.

It was discovered that PHP incorrectly handled certain files. An
attacker could possibly use this issue to access sensitive information.
(CVE-2019-9022)

It was discovered that PHP incorrectly handled certain files. An
attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-9675)

Original advisory details:

 It was discovered that PHP incorrectly handled certain inputs. An
 attacker could possibly use this issue to expose sensitive
 information. (CVE-2019-9637, CVE-2019-9638, CVE-2019-9639,
 CVE-2019-9640, CVE-2019-9641)

References:
  https://usn.ubuntu.com/usn/usn-3922-2
  https://usn.ubuntu.com/usn/usn-3922-1
  CVE-2019-9022, CVE-2019-9637, CVE-2019-9638, CVE-2019-9639,
  CVE-2019-9640, CVE-2019-9641, CVE-2019-9675

沒有留言:

張貼留言