USN-2952-2: PHP regression
USN-2952-2: PHP regression Ubuntu Security Notice USN-2952-2 27th April, 2016 php5 regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Summary USN-2952-1 caused a regression in PHP. Software description php5 – HTML-embedded scripting language interpreter Details USN-2952-1 fixed vulnerabilities in PHP. One of the backported patchescaused a regression in the PHP Soap client. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that the PHP Zip extension incorrectly handled directories when processing certain zip files. A remote attacker could possibly use this issue to create arbitrary directories. (CVE-2014-9767) It was discovered that the PHP Soap client incorrectly validated data types. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2015-8835, CVE-2016-3185) It was discovered [ more… ]