Amazon Linux AMI update for php54



Published: 2014-07-09
Risk High
Patch available YES
Number of vulnerabilities 8
CVE-ID CVE-2014-0207
CVE-2014-3478
CVE-2014-3479
CVE-2014-3480
CVE-2014-3487
CVE-2014-3515
CVE-2014-3981
CVE-2014-4049
CWE-ID CWE-617
CWE-119
CWE-20
CWE-843
CWE-59
CWE-122
Exploitation vector Network
Public exploit Public exploit code for vulnerability #6 is available.
Vulnerable software
Subscribe
Amazon Linux AMI
Operating systems & Components / Operating system

Vendor Amazon Web Services

Security Bulletin

This security bulletin contains information about 8 vulnerabilities.

1) Reachable assertion

EUVDB-ID: #VU16087

Risk: Low

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2014-0207

CWE-ID: CWE-617 - Reachable Assertion

Exploit availability: No

Description

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to assertion failure in the cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14. A remote attacker can trigger reachable assertion via a specially crafted CDF file and cause the service to crash.

Mitigation

Update the affected packages:

i686:
    php54-gd-5.4.30-1.56.amzn1.i686
    php54-intl-5.4.30-1.56.amzn1.i686
    php54-snmp-5.4.30-1.56.amzn1.i686
    php54-mysqlnd-5.4.30-1.56.amzn1.i686
    php54-bcmath-5.4.30-1.56.amzn1.i686
    php54-mbstring-5.4.30-1.56.amzn1.i686
    php54-embedded-5.4.30-1.56.amzn1.i686
    php54-xml-5.4.30-1.56.amzn1.i686
    php54-xmlrpc-5.4.30-1.56.amzn1.i686
    php54-debuginfo-5.4.30-1.56.amzn1.i686
    php54-pdo-5.4.30-1.56.amzn1.i686
    php54-dba-5.4.30-1.56.amzn1.i686
    php54-tidy-5.4.30-1.56.amzn1.i686
    php54-imap-5.4.30-1.56.amzn1.i686
    php54-soap-5.4.30-1.56.amzn1.i686
    php54-5.4.30-1.56.amzn1.i686
    php54-enchant-5.4.30-1.56.amzn1.i686
    php54-devel-5.4.30-1.56.amzn1.i686
    php54-fpm-5.4.30-1.56.amzn1.i686
    php54-common-5.4.30-1.56.amzn1.i686
    php54-cli-5.4.30-1.56.amzn1.i686
    php54-mysql-5.4.30-1.56.amzn1.i686
    php54-odbc-5.4.30-1.56.amzn1.i686
    php54-ldap-5.4.30-1.56.amzn1.i686
    php54-pspell-5.4.30-1.56.amzn1.i686
    php54-mssql-5.4.30-1.56.amzn1.i686
    php54-recode-5.4.30-1.56.amzn1.i686
    php54-mcrypt-5.4.30-1.56.amzn1.i686
    php54-pgsql-5.4.30-1.56.amzn1.i686
    php54-process-5.4.30-1.56.amzn1.i686

src:
    php54-5.4.30-1.56.amzn1.src

x86_64:
    php54-mcrypt-5.4.30-1.56.amzn1.x86_64
    php54-ldap-5.4.30-1.56.amzn1.x86_64
    php54-imap-5.4.30-1.56.amzn1.x86_64
    php54-5.4.30-1.56.amzn1.x86_64
    php54-snmp-5.4.30-1.56.amzn1.x86_64
    php54-pdo-5.4.30-1.56.amzn1.x86_64
    php54-pspell-5.4.30-1.56.amzn1.x86_64
    php54-dba-5.4.30-1.56.amzn1.x86_64
    php54-embedded-5.4.30-1.56.amzn1.x86_64
    php54-bcmath-5.4.30-1.56.amzn1.x86_64
    php54-intl-5.4.30-1.56.amzn1.x86_64
    php54-common-5.4.30-1.56.amzn1.x86_64
    php54-xml-5.4.30-1.56.amzn1.x86_64
    php54-fpm-5.4.30-1.56.amzn1.x86_64
    php54-pgsql-5.4.30-1.56.amzn1.x86_64
    php54-cli-5.4.30-1.56.amzn1.x86_64
    php54-process-5.4.30-1.56.amzn1.x86_64
    php54-soap-5.4.30-1.56.amzn1.x86_64
    php54-tidy-5.4.30-1.56.amzn1.x86_64
    php54-recode-5.4.30-1.56.amzn1.x86_64
    php54-gd-5.4.30-1.56.amzn1.x86_64
    php54-enchant-5.4.30-1.56.amzn1.x86_64
    php54-mssql-5.4.30-1.56.amzn1.x86_64
    php54-debuginfo-5.4.30-1.56.amzn1.x86_64
    php54-mysqlnd-5.4.30-1.56.amzn1.x86_64
    php54-odbc-5.4.30-1.56.amzn1.x86_64
    php54-devel-5.4.30-1.56.amzn1.x86_64
    php54-mysql-5.4.30-1.56.amzn1.x86_64
    php54-mbstring-5.4.30-1.56.amzn1.x86_64
    php54-xmlrpc-5.4.30-1.56.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2014-367.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Buffer overflow

EUVDB-ID: #VU16088

Risk: Low

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2014-3478

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14. A remote attacker can trigger memory corruption via a crafted Pascal string in a FILE_PSTRING conversion and cause the service to crash.

Mitigation

Update the affected packages:

i686:
    php54-gd-5.4.30-1.56.amzn1.i686
    php54-intl-5.4.30-1.56.amzn1.i686
    php54-snmp-5.4.30-1.56.amzn1.i686
    php54-mysqlnd-5.4.30-1.56.amzn1.i686
    php54-bcmath-5.4.30-1.56.amzn1.i686
    php54-mbstring-5.4.30-1.56.amzn1.i686
    php54-embedded-5.4.30-1.56.amzn1.i686
    php54-xml-5.4.30-1.56.amzn1.i686
    php54-xmlrpc-5.4.30-1.56.amzn1.i686
    php54-debuginfo-5.4.30-1.56.amzn1.i686
    php54-pdo-5.4.30-1.56.amzn1.i686
    php54-dba-5.4.30-1.56.amzn1.i686
    php54-tidy-5.4.30-1.56.amzn1.i686
    php54-imap-5.4.30-1.56.amzn1.i686
    php54-soap-5.4.30-1.56.amzn1.i686
    php54-5.4.30-1.56.amzn1.i686
    php54-enchant-5.4.30-1.56.amzn1.i686
    php54-devel-5.4.30-1.56.amzn1.i686
    php54-fpm-5.4.30-1.56.amzn1.i686
    php54-common-5.4.30-1.56.amzn1.i686
    php54-cli-5.4.30-1.56.amzn1.i686
    php54-mysql-5.4.30-1.56.amzn1.i686
    php54-odbc-5.4.30-1.56.amzn1.i686
    php54-ldap-5.4.30-1.56.amzn1.i686
    php54-pspell-5.4.30-1.56.amzn1.i686
    php54-mssql-5.4.30-1.56.amzn1.i686
    php54-recode-5.4.30-1.56.amzn1.i686
    php54-mcrypt-5.4.30-1.56.amzn1.i686
    php54-pgsql-5.4.30-1.56.amzn1.i686
    php54-process-5.4.30-1.56.amzn1.i686

src:
    php54-5.4.30-1.56.amzn1.src

x86_64:
    php54-mcrypt-5.4.30-1.56.amzn1.x86_64
    php54-ldap-5.4.30-1.56.amzn1.x86_64
    php54-imap-5.4.30-1.56.amzn1.x86_64
    php54-5.4.30-1.56.amzn1.x86_64
    php54-snmp-5.4.30-1.56.amzn1.x86_64
    php54-pdo-5.4.30-1.56.amzn1.x86_64
    php54-pspell-5.4.30-1.56.amzn1.x86_64
    php54-dba-5.4.30-1.56.amzn1.x86_64
    php54-embedded-5.4.30-1.56.amzn1.x86_64
    php54-bcmath-5.4.30-1.56.amzn1.x86_64
    php54-intl-5.4.30-1.56.amzn1.x86_64
    php54-common-5.4.30-1.56.amzn1.x86_64
    php54-xml-5.4.30-1.56.amzn1.x86_64
    php54-fpm-5.4.30-1.56.amzn1.x86_64
    php54-pgsql-5.4.30-1.56.amzn1.x86_64
    php54-cli-5.4.30-1.56.amzn1.x86_64
    php54-process-5.4.30-1.56.amzn1.x86_64
    php54-soap-5.4.30-1.56.amzn1.x86_64
    php54-tidy-5.4.30-1.56.amzn1.x86_64
    php54-recode-5.4.30-1.56.amzn1.x86_64
    php54-gd-5.4.30-1.56.amzn1.x86_64
    php54-enchant-5.4.30-1.56.amzn1.x86_64
    php54-mssql-5.4.30-1.56.amzn1.x86_64
    php54-debuginfo-5.4.30-1.56.amzn1.x86_64
    php54-mysqlnd-5.4.30-1.56.amzn1.x86_64
    php54-odbc-5.4.30-1.56.amzn1.x86_64
    php54-devel-5.4.30-1.56.amzn1.x86_64
    php54-mysql-5.4.30-1.56.amzn1.x86_64
    php54-mbstring-5.4.30-1.56.amzn1.x86_64
    php54-xmlrpc-5.4.30-1.56.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2014-367.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Input validation error

EUVDB-ID: #VU16089

Risk: Low

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2014-3479

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when the cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data. A remote attacker can cause the service to crash via a crafted stream offset in a CDF file.

Mitigation

Update the affected packages:

i686:
    php54-gd-5.4.30-1.56.amzn1.i686
    php54-intl-5.4.30-1.56.amzn1.i686
    php54-snmp-5.4.30-1.56.amzn1.i686
    php54-mysqlnd-5.4.30-1.56.amzn1.i686
    php54-bcmath-5.4.30-1.56.amzn1.i686
    php54-mbstring-5.4.30-1.56.amzn1.i686
    php54-embedded-5.4.30-1.56.amzn1.i686
    php54-xml-5.4.30-1.56.amzn1.i686
    php54-xmlrpc-5.4.30-1.56.amzn1.i686
    php54-debuginfo-5.4.30-1.56.amzn1.i686
    php54-pdo-5.4.30-1.56.amzn1.i686
    php54-dba-5.4.30-1.56.amzn1.i686
    php54-tidy-5.4.30-1.56.amzn1.i686
    php54-imap-5.4.30-1.56.amzn1.i686
    php54-soap-5.4.30-1.56.amzn1.i686
    php54-5.4.30-1.56.amzn1.i686
    php54-enchant-5.4.30-1.56.amzn1.i686
    php54-devel-5.4.30-1.56.amzn1.i686
    php54-fpm-5.4.30-1.56.amzn1.i686
    php54-common-5.4.30-1.56.amzn1.i686
    php54-cli-5.4.30-1.56.amzn1.i686
    php54-mysql-5.4.30-1.56.amzn1.i686
    php54-odbc-5.4.30-1.56.amzn1.i686
    php54-ldap-5.4.30-1.56.amzn1.i686
    php54-pspell-5.4.30-1.56.amzn1.i686
    php54-mssql-5.4.30-1.56.amzn1.i686
    php54-recode-5.4.30-1.56.amzn1.i686
    php54-mcrypt-5.4.30-1.56.amzn1.i686
    php54-pgsql-5.4.30-1.56.amzn1.i686
    php54-process-5.4.30-1.56.amzn1.i686

src:
    php54-5.4.30-1.56.amzn1.src

x86_64:
    php54-mcrypt-5.4.30-1.56.amzn1.x86_64
    php54-ldap-5.4.30-1.56.amzn1.x86_64
    php54-imap-5.4.30-1.56.amzn1.x86_64
    php54-5.4.30-1.56.amzn1.x86_64
    php54-snmp-5.4.30-1.56.amzn1.x86_64
    php54-pdo-5.4.30-1.56.amzn1.x86_64
    php54-pspell-5.4.30-1.56.amzn1.x86_64
    php54-dba-5.4.30-1.56.amzn1.x86_64
    php54-embedded-5.4.30-1.56.amzn1.x86_64
    php54-bcmath-5.4.30-1.56.amzn1.x86_64
    php54-intl-5.4.30-1.56.amzn1.x86_64
    php54-common-5.4.30-1.56.amzn1.x86_64
    php54-xml-5.4.30-1.56.amzn1.x86_64
    php54-fpm-5.4.30-1.56.amzn1.x86_64
    php54-pgsql-5.4.30-1.56.amzn1.x86_64
    php54-cli-5.4.30-1.56.amzn1.x86_64
    php54-process-5.4.30-1.56.amzn1.x86_64
    php54-soap-5.4.30-1.56.amzn1.x86_64
    php54-tidy-5.4.30-1.56.amzn1.x86_64
    php54-recode-5.4.30-1.56.amzn1.x86_64
    php54-gd-5.4.30-1.56.amzn1.x86_64
    php54-enchant-5.4.30-1.56.amzn1.x86_64
    php54-mssql-5.4.30-1.56.amzn1.x86_64
    php54-debuginfo-5.4.30-1.56.amzn1.x86_64
    php54-mysqlnd-5.4.30-1.56.amzn1.x86_64
    php54-odbc-5.4.30-1.56.amzn1.x86_64
    php54-devel-5.4.30-1.56.amzn1.x86_64
    php54-mysql-5.4.30-1.56.amzn1.x86_64
    php54-mbstring-5.4.30-1.56.amzn1.x86_64
    php54-xmlrpc-5.4.30-1.56.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2014-367.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Input validation error

EUVDB-ID: #VU16090

Risk: Low

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2014-3480

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of sector-count data by df_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14. A remote attacker can cause application crash via a crafted CDF file.

Mitigation

Update the affected packages:

i686:
    php54-gd-5.4.30-1.56.amzn1.i686
    php54-intl-5.4.30-1.56.amzn1.i686
    php54-snmp-5.4.30-1.56.amzn1.i686
    php54-mysqlnd-5.4.30-1.56.amzn1.i686
    php54-bcmath-5.4.30-1.56.amzn1.i686
    php54-mbstring-5.4.30-1.56.amzn1.i686
    php54-embedded-5.4.30-1.56.amzn1.i686
    php54-xml-5.4.30-1.56.amzn1.i686
    php54-xmlrpc-5.4.30-1.56.amzn1.i686
    php54-debuginfo-5.4.30-1.56.amzn1.i686
    php54-pdo-5.4.30-1.56.amzn1.i686
    php54-dba-5.4.30-1.56.amzn1.i686
    php54-tidy-5.4.30-1.56.amzn1.i686
    php54-imap-5.4.30-1.56.amzn1.i686
    php54-soap-5.4.30-1.56.amzn1.i686
    php54-5.4.30-1.56.amzn1.i686
    php54-enchant-5.4.30-1.56.amzn1.i686
    php54-devel-5.4.30-1.56.amzn1.i686
    php54-fpm-5.4.30-1.56.amzn1.i686
    php54-common-5.4.30-1.56.amzn1.i686
    php54-cli-5.4.30-1.56.amzn1.i686
    php54-mysql-5.4.30-1.56.amzn1.i686
    php54-odbc-5.4.30-1.56.amzn1.i686
    php54-ldap-5.4.30-1.56.amzn1.i686
    php54-pspell-5.4.30-1.56.amzn1.i686
    php54-mssql-5.4.30-1.56.amzn1.i686
    php54-recode-5.4.30-1.56.amzn1.i686
    php54-mcrypt-5.4.30-1.56.amzn1.i686
    php54-pgsql-5.4.30-1.56.amzn1.i686
    php54-process-5.4.30-1.56.amzn1.i686

src:
    php54-5.4.30-1.56.amzn1.src

x86_64:
    php54-mcrypt-5.4.30-1.56.amzn1.x86_64
    php54-ldap-5.4.30-1.56.amzn1.x86_64
    php54-imap-5.4.30-1.56.amzn1.x86_64
    php54-5.4.30-1.56.amzn1.x86_64
    php54-snmp-5.4.30-1.56.amzn1.x86_64
    php54-pdo-5.4.30-1.56.amzn1.x86_64
    php54-pspell-5.4.30-1.56.amzn1.x86_64
    php54-dba-5.4.30-1.56.amzn1.x86_64
    php54-embedded-5.4.30-1.56.amzn1.x86_64
    php54-bcmath-5.4.30-1.56.amzn1.x86_64
    php54-intl-5.4.30-1.56.amzn1.x86_64
    php54-common-5.4.30-1.56.amzn1.x86_64
    php54-xml-5.4.30-1.56.amzn1.x86_64
    php54-fpm-5.4.30-1.56.amzn1.x86_64
    php54-pgsql-5.4.30-1.56.amzn1.x86_64
    php54-cli-5.4.30-1.56.amzn1.x86_64
    php54-process-5.4.30-1.56.amzn1.x86_64
    php54-soap-5.4.30-1.56.amzn1.x86_64
    php54-tidy-5.4.30-1.56.amzn1.x86_64
    php54-recode-5.4.30-1.56.amzn1.x86_64
    php54-gd-5.4.30-1.56.amzn1.x86_64
    php54-enchant-5.4.30-1.56.amzn1.x86_64
    php54-mssql-5.4.30-1.56.amzn1.x86_64
    php54-debuginfo-5.4.30-1.56.amzn1.x86_64
    php54-mysqlnd-5.4.30-1.56.amzn1.x86_64
    php54-odbc-5.4.30-1.56.amzn1.x86_64
    php54-devel-5.4.30-1.56.amzn1.x86_64
    php54-mysql-5.4.30-1.56.amzn1.x86_64
    php54-mbstring-5.4.30-1.56.amzn1.x86_64
    php54-xmlrpc-5.4.30-1.56.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2014-367.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Input validation error

EUVDB-ID: #VU16091

Risk: Low

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2014-3487

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of a stream offset by the cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14. A remote attacker can cause the application to crash via a crafted CDF file.

Mitigation

Update the affected packages:

i686:
    php54-gd-5.4.30-1.56.amzn1.i686
    php54-intl-5.4.30-1.56.amzn1.i686
    php54-snmp-5.4.30-1.56.amzn1.i686
    php54-mysqlnd-5.4.30-1.56.amzn1.i686
    php54-bcmath-5.4.30-1.56.amzn1.i686
    php54-mbstring-5.4.30-1.56.amzn1.i686
    php54-embedded-5.4.30-1.56.amzn1.i686
    php54-xml-5.4.30-1.56.amzn1.i686
    php54-xmlrpc-5.4.30-1.56.amzn1.i686
    php54-debuginfo-5.4.30-1.56.amzn1.i686
    php54-pdo-5.4.30-1.56.amzn1.i686
    php54-dba-5.4.30-1.56.amzn1.i686
    php54-tidy-5.4.30-1.56.amzn1.i686
    php54-imap-5.4.30-1.56.amzn1.i686
    php54-soap-5.4.30-1.56.amzn1.i686
    php54-5.4.30-1.56.amzn1.i686
    php54-enchant-5.4.30-1.56.amzn1.i686
    php54-devel-5.4.30-1.56.amzn1.i686
    php54-fpm-5.4.30-1.56.amzn1.i686
    php54-common-5.4.30-1.56.amzn1.i686
    php54-cli-5.4.30-1.56.amzn1.i686
    php54-mysql-5.4.30-1.56.amzn1.i686
    php54-odbc-5.4.30-1.56.amzn1.i686
    php54-ldap-5.4.30-1.56.amzn1.i686
    php54-pspell-5.4.30-1.56.amzn1.i686
    php54-mssql-5.4.30-1.56.amzn1.i686
    php54-recode-5.4.30-1.56.amzn1.i686
    php54-mcrypt-5.4.30-1.56.amzn1.i686
    php54-pgsql-5.4.30-1.56.amzn1.i686
    php54-process-5.4.30-1.56.amzn1.i686

src:
    php54-5.4.30-1.56.amzn1.src

x86_64:
    php54-mcrypt-5.4.30-1.56.amzn1.x86_64
    php54-ldap-5.4.30-1.56.amzn1.x86_64
    php54-imap-5.4.30-1.56.amzn1.x86_64
    php54-5.4.30-1.56.amzn1.x86_64
    php54-snmp-5.4.30-1.56.amzn1.x86_64
    php54-pdo-5.4.30-1.56.amzn1.x86_64
    php54-pspell-5.4.30-1.56.amzn1.x86_64
    php54-dba-5.4.30-1.56.amzn1.x86_64
    php54-embedded-5.4.30-1.56.amzn1.x86_64
    php54-bcmath-5.4.30-1.56.amzn1.x86_64
    php54-intl-5.4.30-1.56.amzn1.x86_64
    php54-common-5.4.30-1.56.amzn1.x86_64
    php54-xml-5.4.30-1.56.amzn1.x86_64
    php54-fpm-5.4.30-1.56.amzn1.x86_64
    php54-pgsql-5.4.30-1.56.amzn1.x86_64
    php54-cli-5.4.30-1.56.amzn1.x86_64
    php54-process-5.4.30-1.56.amzn1.x86_64
    php54-soap-5.4.30-1.56.amzn1.x86_64
    php54-tidy-5.4.30-1.56.amzn1.x86_64
    php54-recode-5.4.30-1.56.amzn1.x86_64
    php54-gd-5.4.30-1.56.amzn1.x86_64
    php54-enchant-5.4.30-1.56.amzn1.x86_64
    php54-mssql-5.4.30-1.56.amzn1.x86_64
    php54-debuginfo-5.4.30-1.56.amzn1.x86_64
    php54-mysqlnd-5.4.30-1.56.amzn1.x86_64
    php54-odbc-5.4.30-1.56.amzn1.x86_64
    php54-devel-5.4.30-1.56.amzn1.x86_64
    php54-mysql-5.4.30-1.56.amzn1.x86_64
    php54-mbstring-5.4.30-1.56.amzn1.x86_64
    php54-xmlrpc-5.4.30-1.56.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2014-367.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Type Confusion

EUVDB-ID: #VU16092

Risk: High

CVSSv3.1: 8.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2014-3515

CWE-ID: CWE-843 - Type confusion

Exploit availability: Yes

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error in (1) ArrayObject and (2) SPLObjectStorage. when the SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization. A remote attacker can trigger a type confusion error via a crafted string that triggers use of a Hashtable destructor and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected packages:

i686:
    php54-gd-5.4.30-1.56.amzn1.i686
    php54-intl-5.4.30-1.56.amzn1.i686
    php54-snmp-5.4.30-1.56.amzn1.i686
    php54-mysqlnd-5.4.30-1.56.amzn1.i686
    php54-bcmath-5.4.30-1.56.amzn1.i686
    php54-mbstring-5.4.30-1.56.amzn1.i686
    php54-embedded-5.4.30-1.56.amzn1.i686
    php54-xml-5.4.30-1.56.amzn1.i686
    php54-xmlrpc-5.4.30-1.56.amzn1.i686
    php54-debuginfo-5.4.30-1.56.amzn1.i686
    php54-pdo-5.4.30-1.56.amzn1.i686
    php54-dba-5.4.30-1.56.amzn1.i686
    php54-tidy-5.4.30-1.56.amzn1.i686
    php54-imap-5.4.30-1.56.amzn1.i686
    php54-soap-5.4.30-1.56.amzn1.i686
    php54-5.4.30-1.56.amzn1.i686
    php54-enchant-5.4.30-1.56.amzn1.i686
    php54-devel-5.4.30-1.56.amzn1.i686
    php54-fpm-5.4.30-1.56.amzn1.i686
    php54-common-5.4.30-1.56.amzn1.i686
    php54-cli-5.4.30-1.56.amzn1.i686
    php54-mysql-5.4.30-1.56.amzn1.i686
    php54-odbc-5.4.30-1.56.amzn1.i686
    php54-ldap-5.4.30-1.56.amzn1.i686
    php54-pspell-5.4.30-1.56.amzn1.i686
    php54-mssql-5.4.30-1.56.amzn1.i686
    php54-recode-5.4.30-1.56.amzn1.i686
    php54-mcrypt-5.4.30-1.56.amzn1.i686
    php54-pgsql-5.4.30-1.56.amzn1.i686
    php54-process-5.4.30-1.56.amzn1.i686

src:
    php54-5.4.30-1.56.amzn1.src

x86_64:
    php54-mcrypt-5.4.30-1.56.amzn1.x86_64
    php54-ldap-5.4.30-1.56.amzn1.x86_64
    php54-imap-5.4.30-1.56.amzn1.x86_64
    php54-5.4.30-1.56.amzn1.x86_64
    php54-snmp-5.4.30-1.56.amzn1.x86_64
    php54-pdo-5.4.30-1.56.amzn1.x86_64
    php54-pspell-5.4.30-1.56.amzn1.x86_64
    php54-dba-5.4.30-1.56.amzn1.x86_64
    php54-embedded-5.4.30-1.56.amzn1.x86_64
    php54-bcmath-5.4.30-1.56.amzn1.x86_64
    php54-intl-5.4.30-1.56.amzn1.x86_64
    php54-common-5.4.30-1.56.amzn1.x86_64
    php54-xml-5.4.30-1.56.amzn1.x86_64
    php54-fpm-5.4.30-1.56.amzn1.x86_64
    php54-pgsql-5.4.30-1.56.amzn1.x86_64
    php54-cli-5.4.30-1.56.amzn1.x86_64
    php54-process-5.4.30-1.56.amzn1.x86_64
    php54-soap-5.4.30-1.56.amzn1.x86_64
    php54-tidy-5.4.30-1.56.amzn1.x86_64
    php54-recode-5.4.30-1.56.amzn1.x86_64
    php54-gd-5.4.30-1.56.amzn1.x86_64
    php54-enchant-5.4.30-1.56.amzn1.x86_64
    php54-mssql-5.4.30-1.56.amzn1.x86_64
    php54-debuginfo-5.4.30-1.56.amzn1.x86_64
    php54-mysqlnd-5.4.30-1.56.amzn1.x86_64
    php54-odbc-5.4.30-1.56.amzn1.x86_64
    php54-devel-5.4.30-1.56.amzn1.x86_64
    php54-mysql-5.4.30-1.56.amzn1.x86_64
    php54-mbstring-5.4.30-1.56.amzn1.x86_64
    php54-xmlrpc-5.4.30-1.56.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2014-367.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

7) Link following

EUVDB-ID: #VU41567

Risk: Medium

CVSSv3.1: 4.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2014-3981

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

Exploit availability: No

Description

The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

Mitigation

Update the affected packages:

i686:
    php54-gd-5.4.30-1.56.amzn1.i686
    php54-intl-5.4.30-1.56.amzn1.i686
    php54-snmp-5.4.30-1.56.amzn1.i686
    php54-mysqlnd-5.4.30-1.56.amzn1.i686
    php54-bcmath-5.4.30-1.56.amzn1.i686
    php54-mbstring-5.4.30-1.56.amzn1.i686
    php54-embedded-5.4.30-1.56.amzn1.i686
    php54-xml-5.4.30-1.56.amzn1.i686
    php54-xmlrpc-5.4.30-1.56.amzn1.i686
    php54-debuginfo-5.4.30-1.56.amzn1.i686
    php54-pdo-5.4.30-1.56.amzn1.i686
    php54-dba-5.4.30-1.56.amzn1.i686
    php54-tidy-5.4.30-1.56.amzn1.i686
    php54-imap-5.4.30-1.56.amzn1.i686
    php54-soap-5.4.30-1.56.amzn1.i686
    php54-5.4.30-1.56.amzn1.i686
    php54-enchant-5.4.30-1.56.amzn1.i686
    php54-devel-5.4.30-1.56.amzn1.i686
    php54-fpm-5.4.30-1.56.amzn1.i686
    php54-common-5.4.30-1.56.amzn1.i686
    php54-cli-5.4.30-1.56.amzn1.i686
    php54-mysql-5.4.30-1.56.amzn1.i686
    php54-odbc-5.4.30-1.56.amzn1.i686
    php54-ldap-5.4.30-1.56.amzn1.i686
    php54-pspell-5.4.30-1.56.amzn1.i686
    php54-mssql-5.4.30-1.56.amzn1.i686
    php54-recode-5.4.30-1.56.amzn1.i686
    php54-mcrypt-5.4.30-1.56.amzn1.i686
    php54-pgsql-5.4.30-1.56.amzn1.i686
    php54-process-5.4.30-1.56.amzn1.i686

src:
    php54-5.4.30-1.56.amzn1.src

x86_64:
    php54-mcrypt-5.4.30-1.56.amzn1.x86_64
    php54-ldap-5.4.30-1.56.amzn1.x86_64
    php54-imap-5.4.30-1.56.amzn1.x86_64
    php54-5.4.30-1.56.amzn1.x86_64
    php54-snmp-5.4.30-1.56.amzn1.x86_64
    php54-pdo-5.4.30-1.56.amzn1.x86_64
    php54-pspell-5.4.30-1.56.amzn1.x86_64
    php54-dba-5.4.30-1.56.amzn1.x86_64
    php54-embedded-5.4.30-1.56.amzn1.x86_64
    php54-bcmath-5.4.30-1.56.amzn1.x86_64
    php54-intl-5.4.30-1.56.amzn1.x86_64
    php54-common-5.4.30-1.56.amzn1.x86_64
    php54-xml-5.4.30-1.56.amzn1.x86_64
    php54-fpm-5.4.30-1.56.amzn1.x86_64
    php54-pgsql-5.4.30-1.56.amzn1.x86_64
    php54-cli-5.4.30-1.56.amzn1.x86_64
    php54-process-5.4.30-1.56.amzn1.x86_64
    php54-soap-5.4.30-1.56.amzn1.x86_64
    php54-tidy-5.4.30-1.56.amzn1.x86_64
    php54-recode-5.4.30-1.56.amzn1.x86_64
    php54-gd-5.4.30-1.56.amzn1.x86_64
    php54-enchant-5.4.30-1.56.amzn1.x86_64
    php54-mssql-5.4.30-1.56.amzn1.x86_64
    php54-debuginfo-5.4.30-1.56.amzn1.x86_64
    php54-mysqlnd-5.4.30-1.56.amzn1.x86_64
    php54-odbc-5.4.30-1.56.amzn1.x86_64
    php54-devel-5.4.30-1.56.amzn1.x86_64
    php54-mysql-5.4.30-1.56.amzn1.x86_64
    php54-mbstring-5.4.30-1.56.amzn1.x86_64
    php54-xmlrpc-5.4.30-1.56.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2014-367.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Heap-based buffer overflow

EUVDB-ID: #VU16086

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2014-4049

CWE-ID: CWE-122 - Heap-based Buffer Overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to heap-based buffer overflow in the php_parserr function in ext/standard/dns.c. A remote attacker can trigger memory corruption via a crafted DNS TXT record, related to the dns_get_record function and cause the service to crash or execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected packages:

i686:
    php54-gd-5.4.30-1.56.amzn1.i686
    php54-intl-5.4.30-1.56.amzn1.i686
    php54-snmp-5.4.30-1.56.amzn1.i686
    php54-mysqlnd-5.4.30-1.56.amzn1.i686
    php54-bcmath-5.4.30-1.56.amzn1.i686
    php54-mbstring-5.4.30-1.56.amzn1.i686
    php54-embedded-5.4.30-1.56.amzn1.i686
    php54-xml-5.4.30-1.56.amzn1.i686
    php54-xmlrpc-5.4.30-1.56.amzn1.i686
    php54-debuginfo-5.4.30-1.56.amzn1.i686
    php54-pdo-5.4.30-1.56.amzn1.i686
    php54-dba-5.4.30-1.56.amzn1.i686
    php54-tidy-5.4.30-1.56.amzn1.i686
    php54-imap-5.4.30-1.56.amzn1.i686
    php54-soap-5.4.30-1.56.amzn1.i686
    php54-5.4.30-1.56.amzn1.i686
    php54-enchant-5.4.30-1.56.amzn1.i686
    php54-devel-5.4.30-1.56.amzn1.i686
    php54-fpm-5.4.30-1.56.amzn1.i686
    php54-common-5.4.30-1.56.amzn1.i686
    php54-cli-5.4.30-1.56.amzn1.i686
    php54-mysql-5.4.30-1.56.amzn1.i686
    php54-odbc-5.4.30-1.56.amzn1.i686
    php54-ldap-5.4.30-1.56.amzn1.i686
    php54-pspell-5.4.30-1.56.amzn1.i686
    php54-mssql-5.4.30-1.56.amzn1.i686
    php54-recode-5.4.30-1.56.amzn1.i686
    php54-mcrypt-5.4.30-1.56.amzn1.i686
    php54-pgsql-5.4.30-1.56.amzn1.i686
    php54-process-5.4.30-1.56.amzn1.i686

src:
    php54-5.4.30-1.56.amzn1.src

x86_64:
    php54-mcrypt-5.4.30-1.56.amzn1.x86_64
    php54-ldap-5.4.30-1.56.amzn1.x86_64
    php54-imap-5.4.30-1.56.amzn1.x86_64
    php54-5.4.30-1.56.amzn1.x86_64
    php54-snmp-5.4.30-1.56.amzn1.x86_64
    php54-pdo-5.4.30-1.56.amzn1.x86_64
    php54-pspell-5.4.30-1.56.amzn1.x86_64
    php54-dba-5.4.30-1.56.amzn1.x86_64
    php54-embedded-5.4.30-1.56.amzn1.x86_64
    php54-bcmath-5.4.30-1.56.amzn1.x86_64
    php54-intl-5.4.30-1.56.amzn1.x86_64
    php54-common-5.4.30-1.56.amzn1.x86_64
    php54-xml-5.4.30-1.56.amzn1.x86_64
    php54-fpm-5.4.30-1.56.amzn1.x86_64
    php54-pgsql-5.4.30-1.56.amzn1.x86_64
    php54-cli-5.4.30-1.56.amzn1.x86_64
    php54-process-5.4.30-1.56.amzn1.x86_64
    php54-soap-5.4.30-1.56.amzn1.x86_64
    php54-tidy-5.4.30-1.56.amzn1.x86_64
    php54-recode-5.4.30-1.56.amzn1.x86_64
    php54-gd-5.4.30-1.56.amzn1.x86_64
    php54-enchant-5.4.30-1.56.amzn1.x86_64
    php54-mssql-5.4.30-1.56.amzn1.x86_64
    php54-debuginfo-5.4.30-1.56.amzn1.x86_64
    php54-mysqlnd-5.4.30-1.56.amzn1.x86_64
    php54-odbc-5.4.30-1.56.amzn1.x86_64
    php54-devel-5.4.30-1.56.amzn1.x86_64
    php54-mysql-5.4.30-1.56.amzn1.x86_64
    php54-mbstring-5.4.30-1.56.amzn1.x86_64
    php54-xmlrpc-5.4.30-1.56.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2014-367.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###