Upstream information
CVE-2012-2386 at MITRE
Description
Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.
NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Note from the SUSE Security Team
This issue does not affect the PHP 5.2 versions in SUSE Linux Enterprise 10 and 11. PHP 5.3 and newer versions were fixed where available.
Novell Bugzilla entry:
763814
SUSE Security Advisories:
List of released packages
| Product(s) | Fixed package version(s) | References |
| SLE 11 SP2 DEBUGINFO | php53-debuginfo >= 5.3.8-0.33.2 php53-debugsource >= 5.3.8-0.33.2
| Builds SAT Patch Nr: 6440 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 | php53-devel >= 5.3.8-0.33.2 php53-imap >= 5.3.8-0.33.2 php53-posix >= 5.3.8-0.33.2 php53-readline >= 5.3.8-0.33.2 php53-sockets >= 5.3.8-0.33.2 php53-sqlite >= 5.3.8-0.33.2 php53-tidy >= 5.3.8-0.33.2
| Builds SAT Patch Nr: 6440 |
SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware | apache2-mod_php53 >= 5.3.8-0.33.2 php53 >= 5.3.8-0.33.2 php53-bcmath >= 5.3.8-0.33.2 php53-bz2 >= 5.3.8-0.33.2 php53-calendar >= 5.3.8-0.33.2 php53-ctype >= 5.3.8-0.33.2 php53-curl >= 5.3.8-0.33.2 php53-dba >= 5.3.8-0.33.2 php53-dom >= 5.3.8-0.33.2 php53-exif >= 5.3.8-0.33.2 php53-fastcgi >= 5.3.8-0.33.2 php53-fileinfo >= 5.3.8-0.33.2 php53-ftp >= 5.3.8-0.33.2 php53-gd >= 5.3.8-0.33.2 php53-gettext >= 5.3.8-0.33.2 php53-gmp >= 5.3.8-0.33.2 php53-iconv >= 5.3.8-0.33.2 php53-intl >= 5.3.8-0.33.2 php53-json >= 5.3.8-0.33.2 php53-ldap >= 5.3.8-0.33.2 php53-mbstring >= 5.3.8-0.33.2 php53-mcrypt >= 5.3.8-0.33.2 php53-mysql >= 5.3.8-0.33.2 php53-odbc >= 5.3.8-0.33.2 php53-openssl >= 5.3.8-0.33.2 php53-pcntl >= 5.3.8-0.33.2 php53-pdo >= 5.3.8-0.33.2 php53-pear >= 5.3.8-0.33.2 php53-pgsql >= 5.3.8-0.33.2 php53-pspell >= 5.3.8-0.33.2 php53-shmop >= 5.3.8-0.33.2 php53-snmp >= 5.3.8-0.33.2 php53-soap >= 5.3.8-0.33.2 php53-suhosin >= 5.3.8-0.33.2 php53-sysvmsg >= 5.3.8-0.33.2 php53-sysvsem >= 5.3.8-0.33.2 php53-sysvshm >= 5.3.8-0.33.2 php53-tokenizer >= 5.3.8-0.33.2 php53-wddx >= 5.3.8-0.33.2 php53-xmlreader >= 5.3.8-0.33.2 php53-xmlrpc >= 5.3.8-0.33.2 php53-xmlwriter >= 5.3.8-0.33.2 php53-xsl >= 5.3.8-0.33.2 php53-zip >= 5.3.8-0.33.2 php53-zlib >= 5.3.8-0.33.2
| Builds SAT Patch Nr: 6440 |