File _patchinfo of Package patchinfo.4542
<patchinfo incident="4542"> <issue id="962057" tracker="bnc">VUL-0: CVE-2016-1903: php5: Memory Read via gdImageRotateInterpolated Array Index Out of Bounds</issue> <issue id="949961" tracker="bnc">VUL-1: CVE-2015-7803: php5,php53: Null pointer dereference in phar_get_fp_offset()</issue> <issue id="949962" tracker="bnc">VUL-1: CVE-2015-7804: php5,php53: Uninitialized pointer in phar_make_dirstream when zip entry filename is "/"</issue> <issue id="CVE-2015-7803" tracker="cve" /> <issue id="CVE-2015-7804" tracker="cve" /> <issue id="CVE-2016-1903" tracker="cve" /> <category>security</category> <rating>moderate</rating> <packager>pgajdos</packager> <description> This update for php5 fixes the following issues: - CVE-2015-7803: Specially crafted .phar files with a crafted TAR archive entry allowed remote attackers to cause a Denial of Service (DoS) [bsc#949961] - CVE-2015-7804: Specially crafted .phar files with a crafted ZIP archive entry referencing a file "/" allowed remote attackers to cause a Denial of Service (DoS) or potentially leak unspecified memory content [bsc#949961] - CVE-2016-1903: Specially crafted image files could allowed remote attackers read unspecified memory when rotating images [bsc#962057] </description> <summary>Security update for php5</summary> </patchinfo>