-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 09 May 2018 16:20:11 +0200 Source: php5 Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm libphp5-embed php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-imap php5-interbase php5-intl php5-ldap php5-mcrypt php5-mysql php5-mysqlnd php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl Architecture: source amd64 all Version: 5.4.45-0+deb7u14 Distribution: wheezy-security Urgency: high Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module) libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo libphp5-embed - HTML-embedded scripting language (Embedded SAPI library) php-pear - PEAR - PHP Extension and Application Repository php5 - server-side, HTML-embedded scripting language (metapackage) php5-cgi - server-side, HTML-embedded scripting language (CGI binary) php5-cli - command-line interpreter for the php5 scripting language php5-common - Common files for packages built from the php5 source php5-curl - CURL module for php5 php5-dbg - Debug symbols for PHP5 php5-dev - Files for PHP5 module development php5-enchant - Enchant module for php5 php5-fpm - server-side, HTML-embedded scripting language (FPM-CGI binary) php5-gd - GD module for php5 php5-gmp - GMP module for php5 php5-imap - IMAP module for php5 php5-interbase - interbase/firebird module for php5 php5-intl - internationalisation module for php5 php5-ldap - LDAP module for php5 php5-mcrypt - MCrypt module for php5 php5-mysql - MySQL module for php5 php5-mysqlnd - MySQL module for php5 (Native Driver) php5-odbc - ODBC module for php5 php5-pgsql - PostgreSQL module for php5 php5-pspell - pspell module for php5 php5-recode - recode module for php5 php5-snmp - SNMP module for php5 php5-sqlite - SQLite module for php5 php5-sybase - Sybase / MS SQL Server module for php5 php5-tidy - tidy module for php5 php5-xmlrpc - XML-RPC module for php5 php5-xsl - XSL module for php5 Changes: php5 (5.4.45-0+deb7u14) wheezy-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix the following CVE: - CVE-2018-10545: Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from the process memory of a second user's PHP applications by running gcore on the PID of the PHP-FPM worker process. - CVE-2018-10547: There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a request for a .phar file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-5712. - CVE-2018-10548: ext/ldap/ldap.c allows remote LDAP servers to cause a denial of service (NULL pointer dereference and application crash) because of mishandling of the ldap_get_dn return value. Checksums-Sha1: 34c7cfe9967d724f17b9ce1f8091441aa3e5eecc 4595 php5_5.4.45-0+deb7u14.dsc 98d1795d5dd17b345aa4838926d18d5a3c45284d 338294 php5_5.4.45-0+deb7u14.debian.tar.gz ef1f5134911d49da8b26478142f40395e90d7aed 648366 php5-common_5.4.45-0+deb7u14_amd64.deb 2f63de9156431008c25019d15c0038bc5ee62fd3 2691380 libapache2-mod-php5_5.4.45-0+deb7u14_amd64.deb df2e4c634a67e6f8a77453bd36b4f0d936289750 2690016 libapache2-mod-php5filter_5.4.45-0+deb7u14_amd64.deb a1eda476255cb4bd66dc65e72a8312522ccfad7a 5152150 php5-cgi_5.4.45-0+deb7u14_amd64.deb b26ddf825feb7951ed7972c4e0d57d92fd00fbb0 2582818 php5-cli_5.4.45-0+deb7u14_amd64.deb f0d9a5bf8fec74465ce729d947d25a36495754f3 2615564 php5-fpm_5.4.45-0+deb7u14_amd64.deb f9c7d96bc0b9379974094502578cc0778ffa847d 2687910 libphp5-embed_5.4.45-0+deb7u14_amd64.deb 7f53adc9e6d6dd0d094c69afc0ddbfde078aa5a4 499360 php5-dev_5.4.45-0+deb7u14_amd64.deb e92416a7a62736c4ddd18498bc468fb2d9575f2e 15932016 php5-dbg_5.4.45-0+deb7u14_amd64.deb 48df2e828bb735ade3eb16f05c2caac40423ae9b 29514 php5-curl_5.4.45-0+deb7u14_amd64.deb d017d165d070c32a471f96e27bf24c267d19b7c0 9912 php5-enchant_5.4.45-0+deb7u14_amd64.deb 181cea57c582b19719231669f8d41a2bdf32d35b 35714 php5-gd_5.4.45-0+deb7u14_amd64.deb 869cdff919bd982c5f4a50cdaea0b7de24e4a2d2 17026 php5-gmp_5.4.45-0+deb7u14_amd64.deb fedc179015ee2274142a1386970d79f04d25a2c0 35614 php5-imap_5.4.45-0+deb7u14_amd64.deb b60720d1887333ade6cdb0197b976dea59fddd95 49640 php5-interbase_5.4.45-0+deb7u14_amd64.deb 170425a5fcdc311e9ffb56260df87e1b2e022ea9 72356 php5-intl_5.4.45-0+deb7u14_amd64.deb 9d09df45ae6b42a978036e9f57dffd61f91891bd 23932 php5-ldap_5.4.45-0+deb7u14_amd64.deb f99673498244e7e3aab0b6d52fd18396ca294b33 16160 php5-mcrypt_5.4.45-0+deb7u14_amd64.deb a3d887b858b56f94fd64a57bd3b468964e6176ce 80868 php5-mysql_5.4.45-0+deb7u14_amd64.deb 3973c74e671b5cd383ec72b4179ee756d7874f3c 164460 php5-mysqlnd_5.4.45-0+deb7u14_amd64.deb 53d6562b3c5def2847877088f632596a5d0ad3f4 36870 php5-odbc_5.4.45-0+deb7u14_amd64.deb 7e421fb3adbb2fdef95289cc9e5c041945ab5879 64324 php5-pgsql_5.4.45-0+deb7u14_amd64.deb 622e1a578274307e957bac3dd22a1af58a1e8852 8916 php5-pspell_5.4.45-0+deb7u14_amd64.deb 31dd808300d6bd6a1b12d9f8f9aaf24430bad18b 5208 php5-recode_5.4.45-0+deb7u14_amd64.deb 68914db05310febf06a794ac39fd8a9123000da5 21966 php5-snmp_5.4.45-0+deb7u14_amd64.deb 549b875ea79c2efe6d30629b9337d4b8ecad1e2f 30498 php5-sqlite_5.4.45-0+deb7u14_amd64.deb be0bc1543318256c882e89b0aa2f41b8f0a3ca66 28934 php5-sybase_5.4.45-0+deb7u14_amd64.deb df3167820a57fa7106762b531d0cbb3503b23435 19662 php5-tidy_5.4.45-0+deb7u14_amd64.deb a0b5f89f839bc1e7f1779def1527f35991c8392e 36504 php5-xmlrpc_5.4.45-0+deb7u14_amd64.deb 2548effa74f4d6051219b276277f5ef3e4284727 15494 php5-xsl_5.4.45-0+deb7u14_amd64.deb 3898187c0bf3568f4f3cb2b45357e722493b6616 1028 php5_5.4.45-0+deb7u14_all.deb 2289e8da303a9ce2d57e75b6f09942f6477223b2 373060 php-pear_5.4.45-0+deb7u14_all.deb Checksums-Sha256: 66bce0fb996ae406da97a1e269a4178b32c7c7594f69f7cb8c90f14ca660a61f 4595 php5_5.4.45-0+deb7u14.dsc 294f05bf265af629594dbf4ac81254fea1dbd379b92b4d3f216bbb80f540a832 338294 php5_5.4.45-0+deb7u14.debian.tar.gz bd447780728039025bdf79f13d2824fbc0439e33fb5506c7946aae41dc52ce4b 648366 php5-common_5.4.45-0+deb7u14_amd64.deb 059f140cc5f0a6a74f48bc2d4021d3662875ceaee2d9e56bcd5265b6ff015a27 2691380 libapache2-mod-php5_5.4.45-0+deb7u14_amd64.deb a050ad3315930dc7ba8556cf81b99f86fef9c1d797fe698e4a2b3afd131f7c36 2690016 libapache2-mod-php5filter_5.4.45-0+deb7u14_amd64.deb f490e3b617116ded3fd3d996b9dd63039a15f42eab1e51f1988fc3ab34b5b6cb 5152150 php5-cgi_5.4.45-0+deb7u14_amd64.deb 29f3fbe3026afd13cdaf86f6d3ca52a3da11f7ac4007d721edc00cf6be377232 2582818 php5-cli_5.4.45-0+deb7u14_amd64.deb c2b9e4e46a840d7cd4f99d94c731628f9d021117f024fb2d8dd9b7d1e77226ae 2615564 php5-fpm_5.4.45-0+deb7u14_amd64.deb 2fc2d85e6cd0925ad300a8a1f931b06d31ecc0a0ced1a3a9e891af5da11746c6 2687910 libphp5-embed_5.4.45-0+deb7u14_amd64.deb 3331ff82b767ab6deb70736606868028c37dfca281f8741ba9e03f472974fe21 499360 php5-dev_5.4.45-0+deb7u14_amd64.deb 24636c62f24a97307c173f4b3d131dc42761ab2768740711f8cb6b777fcfd79b 15932016 php5-dbg_5.4.45-0+deb7u14_amd64.deb 1e74455dd493229e84cc36bed6430c9b8cd083973afa89e8c99c155eca3873bb 29514 php5-curl_5.4.45-0+deb7u14_amd64.deb ecd0bf2e8c5e142d49a723e5c3551be58ea4f04a12e3e3d723c8b1522ad7a2ae 9912 php5-enchant_5.4.45-0+deb7u14_amd64.deb a7517c516be542c2d4087a0a67dc2bec24996d2f6445ad53fffc7ac9802a4cb2 35714 php5-gd_5.4.45-0+deb7u14_amd64.deb c529d90f1b1fee78f356c5beb500ff5445b3b08fb52e580e36fceddd3ff99552 17026 php5-gmp_5.4.45-0+deb7u14_amd64.deb 9d610f5bdd8b5a9587e993e2f0d9ace957a336ec08a0fd0439de601d755588ee 35614 php5-imap_5.4.45-0+deb7u14_amd64.deb 9673fda7ede92294a7bb10c157d39fbe04169c20eb0cdc7851d4353018ef7c66 49640 php5-interbase_5.4.45-0+deb7u14_amd64.deb 39346fb1c644eb2671f81ed26241fddd9a0a62dcdc79e1f987a4affa599eb8f4 72356 php5-intl_5.4.45-0+deb7u14_amd64.deb f10e6d012e377ddf2f361d59330f260e773aaac4572adf3e179b3afa85a080df 23932 php5-ldap_5.4.45-0+deb7u14_amd64.deb a1a295d45ecdcd54d630fb04e05d39c50785e1272a54495048d89d4abb5f5a37 16160 php5-mcrypt_5.4.45-0+deb7u14_amd64.deb 8253884a848001b35a7acbc3cf956810a17a572c4af5c0e106e44b4a93fc3144 80868 php5-mysql_5.4.45-0+deb7u14_amd64.deb 20eca07b4265564a6983db0184042f0efb26d48f46484ac30d5a5d68bfb0ec2e 164460 php5-mysqlnd_5.4.45-0+deb7u14_amd64.deb 41c44fa34522413f8e2a101b6cf4723936427e235567c53c33b5aceb4a3e2677 36870 php5-odbc_5.4.45-0+deb7u14_amd64.deb 297db6a5331d8ecb6dcdc209b9738c30900ee61a41f8f00601f76886e9eb4681 64324 php5-pgsql_5.4.45-0+deb7u14_amd64.deb e51958ce876fa770c0dff7ea250481bc5a1f61c4d90e1a221b03e124d57c08ca 8916 php5-pspell_5.4.45-0+deb7u14_amd64.deb 57e62e4bddcdc860c970a96f53f4bb0b1d8fc0183f32a1c62c2da75296a9f342 5208 php5-recode_5.4.45-0+deb7u14_amd64.deb c970821f55553c5b7c5ca30ae8ec8c7d2ac231de4e1afef82066b232daa2fd39 21966 php5-snmp_5.4.45-0+deb7u14_amd64.deb ceba1634dfcb6b57203fecacabd5fd1ecbf3df4084a8aeda057321237378662f 30498 php5-sqlite_5.4.45-0+deb7u14_amd64.deb 41cda4b77f49ffa5bea89a422d204e9dedd67f6b4c56f417de0097e7a4b6af17 28934 php5-sybase_5.4.45-0+deb7u14_amd64.deb 59f652ce5066495ede21449845f1d0a9b046eb42719d456c181877dc9c1e2208 19662 php5-tidy_5.4.45-0+deb7u14_amd64.deb bfe4da8c7e8429f5ebbd8858a0d4b7c7cd2079b49a19b63c233309bbb92fe2e5 36504 php5-xmlrpc_5.4.45-0+deb7u14_amd64.deb b98127dee16d3250c43f9da01f94aa5c2ba69c64ff4cca5faa5475c23dc6e555 15494 php5-xsl_5.4.45-0+deb7u14_amd64.deb 89d0f1e45cceca3a063c473d662f5d315d994be2ec907f74bad24afa2f8147d1 1028 php5_5.4.45-0+deb7u14_all.deb aa6553132a546309c69d6f295109510f147ae3982f5e659d08c8c2f49b28afd6 373060 php-pear_5.4.45-0+deb7u14_all.deb Files: 413d5a00218385d40f55ad51d9c62a6f 4595 php optional php5_5.4.45-0+deb7u14.dsc 90b12699fe3a94c755d386bb94616fac 338294 php optional php5_5.4.45-0+deb7u14.debian.tar.gz 5925af4e40c95f789c9bfa3d4b3d8ca6 648366 php optional php5-common_5.4.45-0+deb7u14_amd64.deb 36ae0b2a1f9605ea950fdb57d87ecd3e 2691380 httpd optional libapache2-mod-php5_5.4.45-0+deb7u14_amd64.deb 1c6d868f5717d48f65c4066e078639be 2690016 httpd extra libapache2-mod-php5filter_5.4.45-0+deb7u14_amd64.deb 669a91a9f9a405dac9daa73adac6ade8 5152150 php optional php5-cgi_5.4.45-0+deb7u14_amd64.deb 86fb68f47d45c7c6ac31a7f39dc01c90 2582818 php optional php5-cli_5.4.45-0+deb7u14_amd64.deb 2fa51fc5fa68358a1b59fc53eedef43a 2615564 php optional php5-fpm_5.4.45-0+deb7u14_amd64.deb cf2b6cccb4cb637580efd5be8fe640f3 2687910 php optional libphp5-embed_5.4.45-0+deb7u14_amd64.deb aadf5ede693af7ab0867b30677929ec2 499360 php optional php5-dev_5.4.45-0+deb7u14_amd64.deb 47db29b65d14226ec2468c9e7caf7b51 15932016 debug extra php5-dbg_5.4.45-0+deb7u14_amd64.deb 87174a3e0df2c0649543766411c55b6b 29514 php optional php5-curl_5.4.45-0+deb7u14_amd64.deb a94d07f402289709e3dce24f2113692a 9912 php optional php5-enchant_5.4.45-0+deb7u14_amd64.deb 84d98c8c3e8e22a7ac1c3bbbfc730bb2 35714 php optional php5-gd_5.4.45-0+deb7u14_amd64.deb d2d63eeeab801c86541a184bc3a83d7b 17026 php optional php5-gmp_5.4.45-0+deb7u14_amd64.deb 06150b7abb070903763c6198a81f8c7f 35614 php optional php5-imap_5.4.45-0+deb7u14_amd64.deb e7250ad9a824c95d6a4d880dc16729ec 49640 php optional php5-interbase_5.4.45-0+deb7u14_amd64.deb c55bdb357aebdafd70c556dc1706039e 72356 php optional php5-intl_5.4.45-0+deb7u14_amd64.deb e64b431f976e3d6dada1438b426f9e2c 23932 php optional php5-ldap_5.4.45-0+deb7u14_amd64.deb 0fdbb511c7317c45e890dbaa7ee5431a 16160 php optional php5-mcrypt_5.4.45-0+deb7u14_amd64.deb 91ad9f419469844b3d1aec553d7d11ed 80868 php optional php5-mysql_5.4.45-0+deb7u14_amd64.deb 25b8f002faa63562ef90af53853a0d2a 164460 php extra php5-mysqlnd_5.4.45-0+deb7u14_amd64.deb 459673a87a1a1e65f4d385e4764ffa87 36870 php optional php5-odbc_5.4.45-0+deb7u14_amd64.deb 12baeb0f70600137925673f06757edae 64324 php optional php5-pgsql_5.4.45-0+deb7u14_amd64.deb c4fa0f9cbf42025dc10d64664acf413e 8916 php optional php5-pspell_5.4.45-0+deb7u14_amd64.deb b43117118be469af5799a1c51f587955 5208 php optional php5-recode_5.4.45-0+deb7u14_amd64.deb f879568e60ddaad14cff657eda266ae1 21966 php optional php5-snmp_5.4.45-0+deb7u14_amd64.deb b06003b6c1ba9c79d7cda661b8d0b2a6 30498 php optional php5-sqlite_5.4.45-0+deb7u14_amd64.deb ad84a14d1adb179a0533554af64a48cf 28934 php optional php5-sybase_5.4.45-0+deb7u14_amd64.deb 4cc2681c797832ed997c4f1fe1f7a84c 19662 php optional php5-tidy_5.4.45-0+deb7u14_amd64.deb 389d92f361059f4fe70a9c4841987d94 36504 php optional php5-xmlrpc_5.4.45-0+deb7u14_amd64.deb e7cd43590e642f3beb87e631e8bb08da 15494 php optional php5-xsl_5.4.45-0+deb7u14_amd64.deb 6e0e1915ac3b1ef8386b85faf6afd9e1 1028 php optional php5_5.4.45-0+deb7u14_all.deb 0f6e309cf524a121417a28a63a52e8da 373060 php optional php-pear_5.4.45-0+deb7u14_all.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlrzOvdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkoVcQAI7L5kiyu3U/KPK8+JupzDCPqFtmYmJeQCAu SLK9vLFobQ4X7ags4lzuafsBYa+HOru0T5XZr/CEQRmmh4I0/9BF6tsVgc6vxSTA 5WkyEtayAzJ+sktKaSJ91MWNOvBbxJQze4ZzKVhAuEI1Pyk1O2SmeQWNVRL85J+u +yNzEmsOZS+4snW94yEh+R8e96ULflxA8KJtoaJ5l+NUTmb5uXTHLw8wTXlhPO/c A2mEgQNeNdDjhrmylMBzw2ONrT6kez27fw6h7cFW7AtjTfQSTKgkquQ6K++2j4+K eb8e+nrRKjWS7CVOWrLPvu61Kv6U3crzbg4wris6RNilUCuSEdQ7eq5pABBw0Bjb BmtY44wsEogAMm3KBK0uCJJQwMkWmTdHVafn4HhnsEJgBpx64299khizxfgdvuJO phEgMSLzuAoK8UVFYfHblECKFPMDwZ8TcmS4LsYCJvCpi2GB2aCVvel7kxjk+7ub SW3Tjb2bvw1dq5JtlAy0o7o2IWMFcRhAEJ3IYSvxSMYhdxIWIXxnIMM4j6lyEBKn iBVbYo917QQxevMlwvbtQjlp4yeSS/yeTk305VaEU0K0YB1DML9NuiJZUe7b6BBv /dEeX8zw3MZYaLAsCsYL4Iy7tRQK9i5DqSt4bPmDC223fZTONrOMjubbpJuwnthi CKxVRmzx =ibDA -----END PGP SIGNATURE-----