Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 599326 - <dev-lang/php-{5.6.28,7.0.13}: Multiple vulnerabilities
Summary: <dev-lang/php-{5.6.28,7.0.13}: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [glsa]
Keywords:
Depends on:
Blocks: 597586
  Show dependency tree
 
Reported: 2016-11-09 18:51 UTC by Thomas Deutschmann (RETIRED)
Modified: 2016-11-30 22:01 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann (RETIRED) gentoo-dev 2016-11-09 18:51:34 UTC
From

 - https://github.com/php/php-src/blob/php-7.0.13/NEWS
 - https://github.com/php/php-src/blob/php-5.6.28/NEWS

-GD:
  - Integer overflow in imageline() with antialiasing
    https://bugs.php.net/73213

  - Integer overflow in gdImageScaleBilinearPalette()
    https://bugs.php.net/73279

  - Stack Buffer Overflow in GD dynamicGetbuf
    https://bugs.php.net/73280

  - Illegal write/read access caused by gdImageAALine overflow).
    https://bugs.php.net/72482

  - imagefilltoborder stackoverflow on truecolor images
    https://bugs.php.net/72696

- Imap:
  - Integer Overflow in "_php_imap_mail" leads Heap Overflow
    https://bugs.php.net/73418

- SPL:
  - Use-after-free in ArrayObject Deserialization
    https://bugs.php.net/73144

- Standard:
  - Use after free in userspace streams
    https://bugs.php.net/73188

- Wddx:
  - NULL Pointer Dereference in WDDX Packet Deserialization with PDORow
    https://bugs.php.net/73331

(the list maybe incomplete)
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2016-11-09 18:54:22 UTC
@maintainer(s): Source tarballs are already available on the mirrors. Please bump the package and let us know if it is ready for the stabilization or not.
Comment 2 Michael Orlitzky gentoo-dev 2016-11-10 21:29:37 UTC
Fixed versions are in the tree, and v5.6.28 can be stabilized.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2016-11-10 21:59:16 UTC
Arches, please test and mark stable: =dev-lang/php-5.6.28

Target keywords: alpha amd64 arm hppa ia64 ppc ppc64 sparc x86

Thank you!
Comment 4 Agostino Sarubbo gentoo-dev 2016-11-11 09:40:41 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2016-11-11 09:41:11 UTC
x86 stable
Comment 6 Jeroen Roovers (RETIRED) gentoo-dev 2016-11-14 08:13:25 UTC
Stable for PPC64.
Comment 7 Tobias Klausmann (RETIRED) gentoo-dev 2016-11-14 17:20:35 UTC
Stable on alpha.
Comment 8 Tomáš Mózes 2016-11-14 19:24:40 UTC
(In reply to Tobias Klausmann from comment #7)
> Stable on alpha.

Seems that 7.0.13 got stabilized just by accident. Not that I wouldn't like it,but seems we are not ready for that yet :)
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2016-11-17 08:03:03 UTC
Stable for HPPA.
Comment 10 Agostino Sarubbo gentoo-dev 2016-11-27 11:37:56 UTC
arm stable
Comment 11 Agostino Sarubbo gentoo-dev 2016-11-27 11:40:58 UTC
ppc stable
Comment 12 Agostino Sarubbo gentoo-dev 2016-11-28 09:36:12 UTC
sparc stable
Comment 13 Agostino Sarubbo gentoo-dev 2016-11-28 09:39:25 UTC
ia64 stable.

Maintainer(s), please cleanup.
Comment 14 Markus Meier gentoo-dev 2016-11-29 17:42:22 UTC
arm stable, all arches done.
Comment 15 GLSAMaker/CVETool Bot gentoo-dev 2016-11-30 21:49:26 UTC
This issue was resolved and addressed in
 GLSA 201611-22 at https://security.gentoo.org/glsa/201611-22
by GLSA coordinator Aaron Bauman (b-man).