-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 24 Jun 2018 01:07:32 -0400 Source: php5 Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-phpdbg php5-fpm libphp5-embed php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-imap php5-interbase php5-intl php5-ldap php5-mcrypt php5-readline php5-mysql php5-mysqlnd php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl Architecture: source all amd64 Version: 5.6.36+dfsg-0+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org> Changed-By: Roberto C. Sanchez <roberto@debian.org> Description: libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module) libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo libphp5-embed - HTML-embedded scripting language (Embedded SAPI library) php-pear - PEAR - PHP Extension and Application Repository php5 - server-side, HTML-embedded scripting language (metapackage) php5-cgi - server-side, HTML-embedded scripting language (CGI binary) php5-cli - command-line interpreter for the php5 scripting language php5-common - Common files for packages built from the php5 source php5-curl - CURL module for php5 php5-dbg - Debug symbols for PHP5 php5-dev - Files for PHP5 module development php5-enchant - Enchant module for php5 php5-fpm - server-side, HTML-embedded scripting language (FPM-CGI binary) php5-gd - GD module for php5 php5-gmp - GMP module for php5 php5-imap - IMAP module for php5 php5-interbase - interbase/firebird module for php5 php5-intl - internationalisation module for php5 php5-ldap - LDAP module for php5 php5-mcrypt - MCrypt module for php5 php5-mysql - MySQL module for php5 php5-mysqlnd - MySQL module for php5 (Native Driver) php5-odbc - ODBC module for php5 php5-pgsql - PostgreSQL module for php5 php5-phpdbg - server-side, HTML-embedded scripting language (PHPDBG binary) php5-pspell - pspell module for php5 php5-readline - Readline module for php5 php5-recode - recode module for php5 php5-snmp - SNMP module for php5 php5-sqlite - SQLite module for php5 php5-sybase - Sybase / MS SQL Server module for php5 php5-tidy - tidy module for php5 php5-xmlrpc - XML-RPC module for php5 php5-xsl - XSL module for php5 Changes: php5 (5.6.36+dfsg-0+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the LTS Team. * New upstream version 5.6.36+dfsg - [CVE-2018-7584] stack-buffer-overflow while parsing HTTP response - [CVE-2018-10545] Dumpable FPM child processes allow bypassing opcache access controls - [CVE-2018-10546] stream filter convert.iconv leads to infinite loop on invalid sequence - [CVE-2018-10547] fix for CVE-2018-5712 may not be complete - [CVE-2018-10548] Malicious LDAP-Server Response causes Crash - [CVE-2018-10549] Heap Buffer Overflow (READ: 1786) in exif_iif_add_value * Refresh patches on top of PHP 5.6.36 Checksums-Sha1: 79c3dab4547366c983f27d4cd358776779c50749 5068 php5_5.6.36+dfsg-0+deb8u1.dsc da60791810c9dad9b9e2a6d00889d5747615fcec 19434439 php5_5.6.36+dfsg.orig.tar.gz ad415a89486e8ef092ffa838f270a8e9c9f9627f 133904 php5_5.6.36+dfsg-0+deb8u1.debian.tar.xz 76f4d7b689f59e1e40861f35a28f242b78395ad8 1308 php5_5.6.36+dfsg-0+deb8u1_all.deb 100dd04898f8e40b867e2a8d097bc91a9db15304 265598 php-pear_5.6.36+dfsg-0+deb8u1_all.deb fe49256933e314542e645d23d5d8937e42be8f66 743596 php5-common_5.6.36+dfsg-0+deb8u1_amd64.deb 4134ade46c00e8a2c1cb16a9b7ebdee41f7efb3a 2228136 libapache2-mod-php5_5.6.36+dfsg-0+deb8u1_amd64.deb c764fd35372fdf0f65aa7bcfb7b184856a8ee8ba 2228930 libapache2-mod-php5filter_5.6.36+dfsg-0+deb8u1_amd64.deb 3ecfad4628e21da6e6a1cc9317a267d582ddeb33 4315422 php5-cgi_5.6.36+dfsg-0+deb8u1_amd64.deb ba5d39f8d37011c7bb41aa694959f5e0c6164839 2192964 php5-cli_5.6.36+dfsg-0+deb8u1_amd64.deb 8bdf32cad1ff0926f136e64c39ba4279a81427b2 2207730 php5-phpdbg_5.6.36+dfsg-0+deb8u1_amd64.deb ec39df1872b2902a5ba14fb14e1eb00481fb514e 2203194 php5-fpm_5.6.36+dfsg-0+deb8u1_amd64.deb 489504b986e929d0da155fc6cce2f7fef4e86be3 2223580 libphp5-embed_5.6.36+dfsg-0+deb8u1_amd64.deb 8b5e6ca24d59838c25a8489eb23e852edfb56a50 357070 php5-dev_5.6.36+dfsg-0+deb8u1_amd64.deb 250ff82dd0a6afbd60b9ce3e493ce27d51b2a351 51067662 php5-dbg_5.6.36+dfsg-0+deb8u1_amd64.deb 8a0370bae971a9bec902cfd3517ad845b8830567 27988 php5-curl_5.6.36+dfsg-0+deb8u1_amd64.deb 5b2f6ee1015bfbf4552a660eebb1411a30037c17 9456 php5-enchant_5.6.36+dfsg-0+deb8u1_amd64.deb f845a411c38887534b9ad7f6804c891c03f1db22 29210 php5-gd_5.6.36+dfsg-0+deb8u1_amd64.deb 13b397d16bcf8cb4cb358d465d82d0528b4c6dd6 21680 php5-gmp_5.6.36+dfsg-0+deb8u1_amd64.deb db216651f2041e9dc27c57f28537f945c6f5d99c 31624 php5-imap_5.6.36+dfsg-0+deb8u1_amd64.deb 184c3f6a2414b2d40cd8f4ac184ac5aa8f2fdcf7 42816 php5-interbase_5.6.36+dfsg-0+deb8u1_amd64.deb 989b78f885a14b1cb1150757d53f8d036126841e 112574 php5-intl_5.6.36+dfsg-0+deb8u1_amd64.deb 1a10c62a2a537cbdd62ef9b8414b05022de31737 22496 php5-ldap_5.6.36+dfsg-0+deb8u1_amd64.deb 8d09d6f2459de32be608c828d2c5f8a6e858d994 15606 php5-mcrypt_5.6.36+dfsg-0+deb8u1_amd64.deb cf41d13e0f0396b48871eb49824f1cfb5173d2f8 12724 php5-readline_5.6.36+dfsg-0+deb8u1_amd64.deb 0beb21f3ebff3ab847e1408bd9d70102947616c8 65852 php5-mysql_5.6.36+dfsg-0+deb8u1_amd64.deb 766a04fb0cc116dd2df8e7761400c63143c9d4bd 141970 php5-mysqlnd_5.6.36+dfsg-0+deb8u1_amd64.deb 39d5e3776c85778be15cc302801d4d18b2bfced4 32164 php5-odbc_5.6.36+dfsg-0+deb8u1_amd64.deb b67dce83588936d27d34a8178341f954b23d8183 59122 php5-pgsql_5.6.36+dfsg-0+deb8u1_amd64.deb 682fafab6947995d769173406b43cf3051843a29 8376 php5-pspell_5.6.36+dfsg-0+deb8u1_amd64.deb 40f4c6d91af48be355bd08ab42168f93730995bb 5752 php5-recode_5.6.36+dfsg-0+deb8u1_amd64.deb a90a0c4fa206986497142407a857b063fa18de16 19770 php5-snmp_5.6.36+dfsg-0+deb8u1_amd64.deb 337de0222a685befc3bc83de6c7387ba2fde86f7 24826 php5-sqlite_5.6.36+dfsg-0+deb8u1_amd64.deb 4a834f8d562159d998367903b9591f311dc177a4 24740 php5-sybase_5.6.36+dfsg-0+deb8u1_amd64.deb 836cf34c100a2a84b1257847ac0721bb9bcfd441 17020 php5-tidy_5.6.36+dfsg-0+deb8u1_amd64.deb c5d8e194be8667d23bf7280a766e30e9bf289961 35944 php5-xmlrpc_5.6.36+dfsg-0+deb8u1_amd64.deb 96a4f2e3cb16bfa6ae72e529649328070f9ac7fb 14192 php5-xsl_5.6.36+dfsg-0+deb8u1_amd64.deb Checksums-Sha256: 5e7ee703b85b868ff4077b592e5abb23624fc85f6715dee5867f9ac1ea302418 5068 php5_5.6.36+dfsg-0+deb8u1.dsc 1738b049337350e6140a0344a68c5fe7cd738cb984921da896eec47fa52ae3c3 19434439 php5_5.6.36+dfsg.orig.tar.gz a34fbd376ba5cbd8c362f0495b9f445365bc476c8bf6e7e6e5d393bacd23af1e 133904 php5_5.6.36+dfsg-0+deb8u1.debian.tar.xz c070cfb2398d32a90c648e5ce120694ea4e6cb60c511d398174f40b757450471 1308 php5_5.6.36+dfsg-0+deb8u1_all.deb 086bdc4c8ca9df7e27db8569a52671085d012d851fe775c03baaef756b0dd2b5 265598 php-pear_5.6.36+dfsg-0+deb8u1_all.deb f3cfd38ef63bf841fe1373dbfb7c5c197a483514a5cf156e03cbf9c65313b0dc 743596 php5-common_5.6.36+dfsg-0+deb8u1_amd64.deb a2a1976395418144c5c19baf1fdf729bdf2e744cc6e27f75af810d91f383a69f 2228136 libapache2-mod-php5_5.6.36+dfsg-0+deb8u1_amd64.deb af05a81b0e7649040cb9f00caec39e146517c8a7df42a2e932694b1542a44b83 2228930 libapache2-mod-php5filter_5.6.36+dfsg-0+deb8u1_amd64.deb cbf27df6b79697cf4d31bc27497e952b1f80974036c914d938d29c6e32eb0587 4315422 php5-cgi_5.6.36+dfsg-0+deb8u1_amd64.deb f703e95b8f89110770061766f4afae182947682ae4a4a2fae238c4eeba150922 2192964 php5-cli_5.6.36+dfsg-0+deb8u1_amd64.deb 36f46ac66ab786ddeacd6b352025175ce13392633b072b7fb13dada1e770adc9 2207730 php5-phpdbg_5.6.36+dfsg-0+deb8u1_amd64.deb d26a7134ea436102b61b8280afcdf3b29ec3817312a06bd71237964838bed44a 2203194 php5-fpm_5.6.36+dfsg-0+deb8u1_amd64.deb 328d9190d882e95882dd3f2380e961ffdf46c735ec8d6d572f8f4ff42c375616 2223580 libphp5-embed_5.6.36+dfsg-0+deb8u1_amd64.deb 04332b8689726108099816a56d2f3c8f96931766673169b4e78771b4eaab5097 357070 php5-dev_5.6.36+dfsg-0+deb8u1_amd64.deb d9d8ac1456c883ce59a5d0acf34670f8c53f708df752925e3b04ced5283f7f39 51067662 php5-dbg_5.6.36+dfsg-0+deb8u1_amd64.deb b71e9920a4b5940be4d714e6fbccd95c2b4826e7dcb84e6f3107d5a115c23d36 27988 php5-curl_5.6.36+dfsg-0+deb8u1_amd64.deb 9cb54020f3e8899d0457d678b98c195d8584a4338a4fdc80c7faec1087ad4832 9456 php5-enchant_5.6.36+dfsg-0+deb8u1_amd64.deb 5e19c2b570b5993744cd0270f536e678ad10f14fde35a0c724c1a6dfcf344f72 29210 php5-gd_5.6.36+dfsg-0+deb8u1_amd64.deb c126d8b8f006f14f52f7a69cc0ec16ae43dedd665cd0c7a703533ca0d69a6a54 21680 php5-gmp_5.6.36+dfsg-0+deb8u1_amd64.deb 67bd323055801f89d6f7b76a4cd3d119a8937ba5c7965b9650fbda11b160caf8 31624 php5-imap_5.6.36+dfsg-0+deb8u1_amd64.deb ceb8cb9a445f5e14743c98d2e9cf10e2be38579802be3523709f85017bfc7aa0 42816 php5-interbase_5.6.36+dfsg-0+deb8u1_amd64.deb b6aae64f1f94849642afa44e3a48cde449df4ef72755f5abb36a9791e0b3ad59 112574 php5-intl_5.6.36+dfsg-0+deb8u1_amd64.deb 331d58e2407fe8985e1c4400d43505ce0ab69b9f59f773cf2e23fc961c4e7124 22496 php5-ldap_5.6.36+dfsg-0+deb8u1_amd64.deb afc3e647febe9100eadb0e44559afdd6ec45180cb1a35cd78c196d887f853161 15606 php5-mcrypt_5.6.36+dfsg-0+deb8u1_amd64.deb 70078799f9494ff09e88e102cda8a6203f224093d78d1ac34182a31f43252458 12724 php5-readline_5.6.36+dfsg-0+deb8u1_amd64.deb b6b0c631d3a28bada8c8b04d431fe3d33473cf251228c77cab0596169e58fc80 65852 php5-mysql_5.6.36+dfsg-0+deb8u1_amd64.deb fb2da88a89ed3c17ad4da84f63250b6fdd7cb4e5e8d5cec0987a05e4897954b8 141970 php5-mysqlnd_5.6.36+dfsg-0+deb8u1_amd64.deb d63f36b702b91a36558a1da4dee3738f85e325839d333f419c9422cd0609b971 32164 php5-odbc_5.6.36+dfsg-0+deb8u1_amd64.deb 7159af19f17eec531d5cdf83d0d335f634eea95c4a78ceef2488c606a9e50ba6 59122 php5-pgsql_5.6.36+dfsg-0+deb8u1_amd64.deb 3806464d438484017fbedec38f44c305b7719a6d9949039dd00b40a5b955e86b 8376 php5-pspell_5.6.36+dfsg-0+deb8u1_amd64.deb 2150fd7072485804be4616607379dc06c57d8b895874456aa61c1d3a0b331fa2 5752 php5-recode_5.6.36+dfsg-0+deb8u1_amd64.deb 2e831452e61cfc7f9e58ff2fcd85eedcd686362597be0c4b73f1c94992b921ff 19770 php5-snmp_5.6.36+dfsg-0+deb8u1_amd64.deb 1d8edefc43d4869c1ea9befd42b3d8054cf7a65aebb1cb782a4ee55149439c4a 24826 php5-sqlite_5.6.36+dfsg-0+deb8u1_amd64.deb c139e10f79908b236cd586f199795733f364cec45cf178780ef68c2e7f7dcc5d 24740 php5-sybase_5.6.36+dfsg-0+deb8u1_amd64.deb 747128ee2571847ef55511e90ae772e9f2fbf2bd190317cb7cde80933b146f3f 17020 php5-tidy_5.6.36+dfsg-0+deb8u1_amd64.deb e09680d5b8db07056f62ea026850cd87edb77decbc5b456f94bd7c492bb7e6a2 35944 php5-xmlrpc_5.6.36+dfsg-0+deb8u1_amd64.deb 6783fd04f53b8be3e6de20807a75bdccb8bb58849b86fe89f5e7a4f454951277 14192 php5-xsl_5.6.36+dfsg-0+deb8u1_amd64.deb Files: 47c2077fea7b0fcd2e709a3446a238b9 5068 php optional php5_5.6.36+dfsg-0+deb8u1.dsc 34354638a65accf8ced5bcc37f02abe8 19434439 php optional php5_5.6.36+dfsg.orig.tar.gz 6811087fb9861e10f85e19b234effd31 133904 php optional php5_5.6.36+dfsg-0+deb8u1.debian.tar.xz 0977bb97fe06dd3ed00d23e7f7a8837c 1308 php optional php5_5.6.36+dfsg-0+deb8u1_all.deb 7632f56b91aa7bdaf4fa8ddae37fdf63 265598 php optional php-pear_5.6.36+dfsg-0+deb8u1_all.deb b0d87e213d7865cfa96710712891c4de 743596 php optional php5-common_5.6.36+dfsg-0+deb8u1_amd64.deb 1502e2f9d1c09b3862e51a040715bbd3 2228136 httpd optional libapache2-mod-php5_5.6.36+dfsg-0+deb8u1_amd64.deb 91bb34184fecc0e6e8f746378698bba2 2228930 httpd extra libapache2-mod-php5filter_5.6.36+dfsg-0+deb8u1_amd64.deb 86893004a742f4c776f2b149ac8a4220 4315422 php optional php5-cgi_5.6.36+dfsg-0+deb8u1_amd64.deb 993fea1f2a2bfee766383d000a5a0819 2192964 php optional php5-cli_5.6.36+dfsg-0+deb8u1_amd64.deb 11153ec4506436d37ae9977e70feec34 2207730 php optional php5-phpdbg_5.6.36+dfsg-0+deb8u1_amd64.deb 6e52ea745a7d821608c0b719f6ef4de3 2203194 php optional php5-fpm_5.6.36+dfsg-0+deb8u1_amd64.deb b1893194910fe3070cb810794d194a8f 2223580 php optional libphp5-embed_5.6.36+dfsg-0+deb8u1_amd64.deb ccd97bf2e12d59d365e97eb2ff189e20 357070 php optional php5-dev_5.6.36+dfsg-0+deb8u1_amd64.deb 6fd53a6afdd405475626d1cc94198b41 51067662 debug extra php5-dbg_5.6.36+dfsg-0+deb8u1_amd64.deb a10ab6ab2e21bfbf6b6d98322de1c5cb 27988 php optional php5-curl_5.6.36+dfsg-0+deb8u1_amd64.deb d6a73983b1adf2ce39d958f4a5918a61 9456 php optional php5-enchant_5.6.36+dfsg-0+deb8u1_amd64.deb 957c2649bd2c9d0b026f5960d2eba980 29210 php optional php5-gd_5.6.36+dfsg-0+deb8u1_amd64.deb 116d6138a2c48b0e1429fe3bcd564bcd 21680 php optional php5-gmp_5.6.36+dfsg-0+deb8u1_amd64.deb ab8b7da574b77ac509465ecf4d02c338 31624 php optional php5-imap_5.6.36+dfsg-0+deb8u1_amd64.deb 23e99059ee3cd80062b72154aac435c9 42816 php optional php5-interbase_5.6.36+dfsg-0+deb8u1_amd64.deb be148d2f80b0de0c9b49edfffba06214 112574 php optional php5-intl_5.6.36+dfsg-0+deb8u1_amd64.deb ee88a7b59f4aa6e1742b284266d15b6f 22496 php optional php5-ldap_5.6.36+dfsg-0+deb8u1_amd64.deb 71f39f207d8f5692a61f10c0445f94b7 15606 php optional php5-mcrypt_5.6.36+dfsg-0+deb8u1_amd64.deb 9c225b52fae693683aab20e9a894a310 12724 php optional php5-readline_5.6.36+dfsg-0+deb8u1_amd64.deb 3a5bcbee9ccd475cdfb00f7b86d3592f 65852 php optional php5-mysql_5.6.36+dfsg-0+deb8u1_amd64.deb 322b982bd93d4b47fb1277e81cf070d9 141970 php extra php5-mysqlnd_5.6.36+dfsg-0+deb8u1_amd64.deb 502734fbe02ea259d0023dacd15585a9 32164 php optional php5-odbc_5.6.36+dfsg-0+deb8u1_amd64.deb 02fa312f21547f2552aa8b2877d4bd0a 59122 php optional php5-pgsql_5.6.36+dfsg-0+deb8u1_amd64.deb 155ca4e051fa1b4d185391dd4c2890ee 8376 php optional php5-pspell_5.6.36+dfsg-0+deb8u1_amd64.deb b8b9241a41bd117658cd54d61af3ab3c 5752 php optional php5-recode_5.6.36+dfsg-0+deb8u1_amd64.deb 720eafe50395eb05aedd54810b53404a 19770 php optional php5-snmp_5.6.36+dfsg-0+deb8u1_amd64.deb 08eb83ca6c685c9a5821f45a742e49a2 24826 php optional php5-sqlite_5.6.36+dfsg-0+deb8u1_amd64.deb 547922aad751bab3eea875d88dd598d7 24740 php optional php5-sybase_5.6.36+dfsg-0+deb8u1_amd64.deb 1a9611ff6194edeb228bd5b24efb9e56 17020 php optional php5-tidy_5.6.36+dfsg-0+deb8u1_amd64.deb 6eb9e75feafb9adb258b62c3d91b9b8f 35944 php optional php5-xmlrpc_5.6.36+dfsg-0+deb8u1_amd64.deb 1b8e14e6355ec16c35cb15508bb8315a 14192 php optional php5-xsl_5.6.36+dfsg-0+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEIYZ1DR4ae5UL01q7ldFmTdL1kUIFAlsyfpQACgkQldFmTdL1 kUJbdRAAmguEgv0GD90tybfaMZmJVhcapCRXsMD/IbufRMlRtUSQliDx9/U2cQb5 pwSAJ2T80yYUbz2HDZFuIO3PrJcDUbmgRE869GZVOLTykZHF/uFjRvuDzf0LqMkd +zH8dGIfslxOn2PvThovaVhqRL/lmOQEepQwPtDeMOGeUz+kVfpm8ligfSw7AM41 OwL+HRP7KySNMCluzeIZp6ZMed6QiMdaMLqFHhmeIlqn2fvX/z3rA9nlcoMljEGx zWSXzJJu5Sk4os54k21gnnBM4nBi0g+BBUyBxw+CZfYkeK1RM50mMducKs+pkD3N 5i7yJa/q1FPYIXf94P9WRabb1LjGkrb0+y+FLKEDO9+HNac0eyB990/R4sNyoSZu Op82CWHRH3pWskasfaoZTLkj6bYWkqpWAvJrK3jFFM70xwZSXcuKxmn9Rbzczx+c jRDsz36DS+IjWUdiXYIB9GeXWmYVOtcnipJ8/9DdHGN6VcU4NpZt6J7iiyOXHYRl 4Cb9urhF+vbsgU9mtFcys8R3IM3ptHorZ00dQAI9MAHLo4J69d5W5j7p9PgfJp/D /BxpJ1dibHFiwDax1Ha3lAyERXpUKpHe/y5YWDRXFmGKaK9Kfyg2tShqOYeStEtr JUjKx+KuMjEy+S4xLsgsixVyHTkkkGIEUFf4FZKgDjYyVmHz11A= =Kld3 -----END PGP SIGNATURE-----