File _patchinfo of Package patchinfo.3821
<patchinfo incident="3821">
<issue id="1015189" tracker="bnc">VUL-0: CVE-2016-9935: php5,php53,php7: Invalid read when wddx decodes empty boolean element</issue>
<issue id="1015188" tracker="bnc">VUL-0: CVE-2016-9934: php5,php53,php7: NULL Pointer Dereference in WDDX Packet Deserialization with PDORow</issue>
<issue id="1015187" tracker="bnc">VUL-0: CVE-2016-9933: php5,php53,php7: imagefilltoborder stackoverflow on truecolor images</issue>
<issue id="1015191" tracker="bnc">VUL-0: CVE-2016-9936: php: Use After Free in PHP7 unserialize()</issue>
<issue id="2016-9936" tracker="cve" />
<issue id="2016-9934" tracker="cve" />
<issue id="2016-9935" tracker="cve" />
<issue id="2016-9933" tracker="cve" />
<category>security</category>
<rating>moderate</rating>
<packager>pgajdos</packager>
<description>
This update for php7 fixes the following issues:
* CVE-2016-9933 Possible stack overflow on truecolor images handling [bsc#1015187]
* CVE-2016-9934 Dereference from NULL pointer could lead to crash [bsc#1015188]
* CVE-2016-9935 Invalid read could lead to crash [bsc#1015189]
* CVE-2016-9936 Use After free in the function serialize() could lead to crash [bsc#1015191]
</description>
<summary>Security update for php7</summary>
</patchinfo>