Amazon Linux AMI update for php56



Published: 2015-08-17
Risk High
Patch available YES
Number of vulnerabilities 6
CVE-ID CVE-2015-3152
CVE-2015-5589
CVE-2015-5590
CVE-2015-6831
CVE-2015-6832
CVE-2015-6833
CWE-ID CWE-300
CWE-20
CWE-121
CWE-416
CWE-22
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Amazon Linux AMI
Operating systems & Components / Operating system

Vendor Amazon Web Services

Security Bulletin

This security bulletin contains information about 6 vulnerabilities.

1) Man-in-the-middle attack

EUVDB-ID: #VU13112

Risk: Low

CVSSv3.1: 5.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2015-3152

CWE-ID: CWE-300 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')

Exploit availability: No

Description

The vulnerability allows a remote attacker to conduct man-in-the-middle attack on the target system.

The vulnerability exists due to use of the --ssl option to mean that SSL is optional. A remote attacker can conduct man-in-the-middle attack, intercept of the communication channel between the affected app and spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.

Mitigation

Update the affected packages:

i686:
    php56-mbstring-5.6.12-1.116.amzn1.i686
    php56-ldap-5.6.12-1.116.amzn1.i686
    php56-mysqlnd-5.6.12-1.116.amzn1.i686
    php56-soap-5.6.12-1.116.amzn1.i686
    php56-devel-5.6.12-1.116.amzn1.i686
    php56-recode-5.6.12-1.116.amzn1.i686
    php56-snmp-5.6.12-1.116.amzn1.i686
    php56-mssql-5.6.12-1.116.amzn1.i686
    php56-tidy-5.6.12-1.116.amzn1.i686
    php56-intl-5.6.12-1.116.amzn1.i686
    php56-5.6.12-1.116.amzn1.i686
    php56-pspell-5.6.12-1.116.amzn1.i686
    php56-embedded-5.6.12-1.116.amzn1.i686
    php56-gd-5.6.12-1.116.amzn1.i686
    php56-mcrypt-5.6.12-1.116.amzn1.i686
    php56-pgsql-5.6.12-1.116.amzn1.i686
    php56-debuginfo-5.6.12-1.116.amzn1.i686
    php56-enchant-5.6.12-1.116.amzn1.i686
    php56-gmp-5.6.12-1.116.amzn1.i686
    php56-xmlrpc-5.6.12-1.116.amzn1.i686
    php56-fpm-5.6.12-1.116.amzn1.i686
    php56-bcmath-5.6.12-1.116.amzn1.i686
    php56-cli-5.6.12-1.116.amzn1.i686
    php56-dbg-5.6.12-1.116.amzn1.i686
    php56-dba-5.6.12-1.116.amzn1.i686
    php56-common-5.6.12-1.116.amzn1.i686
    php56-odbc-5.6.12-1.116.amzn1.i686
    php56-xml-5.6.12-1.116.amzn1.i686
    php56-imap-5.6.12-1.116.amzn1.i686
    php56-pdo-5.6.12-1.116.amzn1.i686
    php56-opcache-5.6.12-1.116.amzn1.i686
    php56-process-5.6.12-1.116.amzn1.i686

src:
    php56-5.6.12-1.116.amzn1.src

x86_64:
    php56-mbstring-5.6.12-1.116.amzn1.x86_64
    php56-devel-5.6.12-1.116.amzn1.x86_64
    php56-opcache-5.6.12-1.116.amzn1.x86_64
    php56-cli-5.6.12-1.116.amzn1.x86_64
    php56-snmp-5.6.12-1.116.amzn1.x86_64
    php56-dba-5.6.12-1.116.amzn1.x86_64
    php56-odbc-5.6.12-1.116.amzn1.x86_64
    php56-mysqlnd-5.6.12-1.116.amzn1.x86_64
    php56-recode-5.6.12-1.116.amzn1.x86_64
    php56-fpm-5.6.12-1.116.amzn1.x86_64
    php56-enchant-5.6.12-1.116.amzn1.x86_64
    php56-debuginfo-5.6.12-1.116.amzn1.x86_64
    php56-gmp-5.6.12-1.116.amzn1.x86_64
    php56-xml-5.6.12-1.116.amzn1.x86_64
    php56-common-5.6.12-1.116.amzn1.x86_64
    php56-pdo-5.6.12-1.116.amzn1.x86_64
    php56-embedded-5.6.12-1.116.amzn1.x86_64
    php56-tidy-5.6.12-1.116.amzn1.x86_64
    php56-imap-5.6.12-1.116.amzn1.x86_64
    php56-intl-5.6.12-1.116.amzn1.x86_64
    php56-bcmath-5.6.12-1.116.amzn1.x86_64
    php56-xmlrpc-5.6.12-1.116.amzn1.x86_64
    php56-pgsql-5.6.12-1.116.amzn1.x86_64
    php56-process-5.6.12-1.116.amzn1.x86_64
    php56-5.6.12-1.116.amzn1.x86_64
    php56-soap-5.6.12-1.116.amzn1.x86_64
    php56-pspell-5.6.12-1.116.amzn1.x86_64
    php56-dbg-5.6.12-1.116.amzn1.x86_64
    php56-mcrypt-5.6.12-1.116.amzn1.x86_64
    php56-ldap-5.6.12-1.116.amzn1.x86_64
    php56-mssql-5.6.12-1.116.amzn1.x86_64
    php56-gd-5.6.12-1.116.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2015-585.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Input validation error

EUVDB-ID: #VU32405

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2015-5589

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a file pointer before a close operation, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted TAR archive that is mishandled in a Phar::convertToData call.

Mitigation

Update the affected packages:

i686:
    php56-mbstring-5.6.12-1.116.amzn1.i686
    php56-ldap-5.6.12-1.116.amzn1.i686
    php56-mysqlnd-5.6.12-1.116.amzn1.i686
    php56-soap-5.6.12-1.116.amzn1.i686
    php56-devel-5.6.12-1.116.amzn1.i686
    php56-recode-5.6.12-1.116.amzn1.i686
    php56-snmp-5.6.12-1.116.amzn1.i686
    php56-mssql-5.6.12-1.116.amzn1.i686
    php56-tidy-5.6.12-1.116.amzn1.i686
    php56-intl-5.6.12-1.116.amzn1.i686
    php56-5.6.12-1.116.amzn1.i686
    php56-pspell-5.6.12-1.116.amzn1.i686
    php56-embedded-5.6.12-1.116.amzn1.i686
    php56-gd-5.6.12-1.116.amzn1.i686
    php56-mcrypt-5.6.12-1.116.amzn1.i686
    php56-pgsql-5.6.12-1.116.amzn1.i686
    php56-debuginfo-5.6.12-1.116.amzn1.i686
    php56-enchant-5.6.12-1.116.amzn1.i686
    php56-gmp-5.6.12-1.116.amzn1.i686
    php56-xmlrpc-5.6.12-1.116.amzn1.i686
    php56-fpm-5.6.12-1.116.amzn1.i686
    php56-bcmath-5.6.12-1.116.amzn1.i686
    php56-cli-5.6.12-1.116.amzn1.i686
    php56-dbg-5.6.12-1.116.amzn1.i686
    php56-dba-5.6.12-1.116.amzn1.i686
    php56-common-5.6.12-1.116.amzn1.i686
    php56-odbc-5.6.12-1.116.amzn1.i686
    php56-xml-5.6.12-1.116.amzn1.i686
    php56-imap-5.6.12-1.116.amzn1.i686
    php56-pdo-5.6.12-1.116.amzn1.i686
    php56-opcache-5.6.12-1.116.amzn1.i686
    php56-process-5.6.12-1.116.amzn1.i686

src:
    php56-5.6.12-1.116.amzn1.src

x86_64:
    php56-mbstring-5.6.12-1.116.amzn1.x86_64
    php56-devel-5.6.12-1.116.amzn1.x86_64
    php56-opcache-5.6.12-1.116.amzn1.x86_64
    php56-cli-5.6.12-1.116.amzn1.x86_64
    php56-snmp-5.6.12-1.116.amzn1.x86_64
    php56-dba-5.6.12-1.116.amzn1.x86_64
    php56-odbc-5.6.12-1.116.amzn1.x86_64
    php56-mysqlnd-5.6.12-1.116.amzn1.x86_64
    php56-recode-5.6.12-1.116.amzn1.x86_64
    php56-fpm-5.6.12-1.116.amzn1.x86_64
    php56-enchant-5.6.12-1.116.amzn1.x86_64
    php56-debuginfo-5.6.12-1.116.amzn1.x86_64
    php56-gmp-5.6.12-1.116.amzn1.x86_64
    php56-xml-5.6.12-1.116.amzn1.x86_64
    php56-common-5.6.12-1.116.amzn1.x86_64
    php56-pdo-5.6.12-1.116.amzn1.x86_64
    php56-embedded-5.6.12-1.116.amzn1.x86_64
    php56-tidy-5.6.12-1.116.amzn1.x86_64
    php56-imap-5.6.12-1.116.amzn1.x86_64
    php56-intl-5.6.12-1.116.amzn1.x86_64
    php56-bcmath-5.6.12-1.116.amzn1.x86_64
    php56-xmlrpc-5.6.12-1.116.amzn1.x86_64
    php56-pgsql-5.6.12-1.116.amzn1.x86_64
    php56-process-5.6.12-1.116.amzn1.x86_64
    php56-5.6.12-1.116.amzn1.x86_64
    php56-soap-5.6.12-1.116.amzn1.x86_64
    php56-pspell-5.6.12-1.116.amzn1.x86_64
    php56-dbg-5.6.12-1.116.amzn1.x86_64
    php56-mcrypt-5.6.12-1.116.amzn1.x86_64
    php56-ldap-5.6.12-1.116.amzn1.x86_64
    php56-mssql-5.6.12-1.116.amzn1.x86_64
    php56-gd-5.6.12-1.116.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2015-585.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Stack-based buffer overflow

EUVDB-ID: #VU32406

Risk: Medium

CVSSv3.1: 6.4 [AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2015-5590

CWE-ID: CWE-121 - Stack-based buffer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the phar_fix_filepath function in ext/phar/phar.c when processing a large length value, as demonstrated by mishandling of an e-mail attachment by the imap PHP extension. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected packages:

i686:
    php56-mbstring-5.6.12-1.116.amzn1.i686
    php56-ldap-5.6.12-1.116.amzn1.i686
    php56-mysqlnd-5.6.12-1.116.amzn1.i686
    php56-soap-5.6.12-1.116.amzn1.i686
    php56-devel-5.6.12-1.116.amzn1.i686
    php56-recode-5.6.12-1.116.amzn1.i686
    php56-snmp-5.6.12-1.116.amzn1.i686
    php56-mssql-5.6.12-1.116.amzn1.i686
    php56-tidy-5.6.12-1.116.amzn1.i686
    php56-intl-5.6.12-1.116.amzn1.i686
    php56-5.6.12-1.116.amzn1.i686
    php56-pspell-5.6.12-1.116.amzn1.i686
    php56-embedded-5.6.12-1.116.amzn1.i686
    php56-gd-5.6.12-1.116.amzn1.i686
    php56-mcrypt-5.6.12-1.116.amzn1.i686
    php56-pgsql-5.6.12-1.116.amzn1.i686
    php56-debuginfo-5.6.12-1.116.amzn1.i686
    php56-enchant-5.6.12-1.116.amzn1.i686
    php56-gmp-5.6.12-1.116.amzn1.i686
    php56-xmlrpc-5.6.12-1.116.amzn1.i686
    php56-fpm-5.6.12-1.116.amzn1.i686
    php56-bcmath-5.6.12-1.116.amzn1.i686
    php56-cli-5.6.12-1.116.amzn1.i686
    php56-dbg-5.6.12-1.116.amzn1.i686
    php56-dba-5.6.12-1.116.amzn1.i686
    php56-common-5.6.12-1.116.amzn1.i686
    php56-odbc-5.6.12-1.116.amzn1.i686
    php56-xml-5.6.12-1.116.amzn1.i686
    php56-imap-5.6.12-1.116.amzn1.i686
    php56-pdo-5.6.12-1.116.amzn1.i686
    php56-opcache-5.6.12-1.116.amzn1.i686
    php56-process-5.6.12-1.116.amzn1.i686

src:
    php56-5.6.12-1.116.amzn1.src

x86_64:
    php56-mbstring-5.6.12-1.116.amzn1.x86_64
    php56-devel-5.6.12-1.116.amzn1.x86_64
    php56-opcache-5.6.12-1.116.amzn1.x86_64
    php56-cli-5.6.12-1.116.amzn1.x86_64
    php56-snmp-5.6.12-1.116.amzn1.x86_64
    php56-dba-5.6.12-1.116.amzn1.x86_64
    php56-odbc-5.6.12-1.116.amzn1.x86_64
    php56-mysqlnd-5.6.12-1.116.amzn1.x86_64
    php56-recode-5.6.12-1.116.amzn1.x86_64
    php56-fpm-5.6.12-1.116.amzn1.x86_64
    php56-enchant-5.6.12-1.116.amzn1.x86_64
    php56-debuginfo-5.6.12-1.116.amzn1.x86_64
    php56-gmp-5.6.12-1.116.amzn1.x86_64
    php56-xml-5.6.12-1.116.amzn1.x86_64
    php56-common-5.6.12-1.116.amzn1.x86_64
    php56-pdo-5.6.12-1.116.amzn1.x86_64
    php56-embedded-5.6.12-1.116.amzn1.x86_64
    php56-tidy-5.6.12-1.116.amzn1.x86_64
    php56-imap-5.6.12-1.116.amzn1.x86_64
    php56-intl-5.6.12-1.116.amzn1.x86_64
    php56-bcmath-5.6.12-1.116.amzn1.x86_64
    php56-xmlrpc-5.6.12-1.116.amzn1.x86_64
    php56-pgsql-5.6.12-1.116.amzn1.x86_64
    php56-process-5.6.12-1.116.amzn1.x86_64
    php56-5.6.12-1.116.amzn1.x86_64
    php56-soap-5.6.12-1.116.amzn1.x86_64
    php56-pspell-5.6.12-1.116.amzn1.x86_64
    php56-dbg-5.6.12-1.116.amzn1.x86_64
    php56-mcrypt-5.6.12-1.116.amzn1.x86_64
    php56-ldap-5.6.12-1.116.amzn1.x86_64
    php56-mssql-5.6.12-1.116.amzn1.x86_64
    php56-gd-5.6.12-1.116.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2015-585.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Input validation error

EUVDB-ID: #VU40518

Risk: Medium

CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2015-6831

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization. <a href="http://cwe.mitre.org/data/definitions/416.html">CWE-416: Use After Free</a>

Mitigation

Update the affected packages:

i686:
    php56-mbstring-5.6.12-1.116.amzn1.i686
    php56-ldap-5.6.12-1.116.amzn1.i686
    php56-mysqlnd-5.6.12-1.116.amzn1.i686
    php56-soap-5.6.12-1.116.amzn1.i686
    php56-devel-5.6.12-1.116.amzn1.i686
    php56-recode-5.6.12-1.116.amzn1.i686
    php56-snmp-5.6.12-1.116.amzn1.i686
    php56-mssql-5.6.12-1.116.amzn1.i686
    php56-tidy-5.6.12-1.116.amzn1.i686
    php56-intl-5.6.12-1.116.amzn1.i686
    php56-5.6.12-1.116.amzn1.i686
    php56-pspell-5.6.12-1.116.amzn1.i686
    php56-embedded-5.6.12-1.116.amzn1.i686
    php56-gd-5.6.12-1.116.amzn1.i686
    php56-mcrypt-5.6.12-1.116.amzn1.i686
    php56-pgsql-5.6.12-1.116.amzn1.i686
    php56-debuginfo-5.6.12-1.116.amzn1.i686
    php56-enchant-5.6.12-1.116.amzn1.i686
    php56-gmp-5.6.12-1.116.amzn1.i686
    php56-xmlrpc-5.6.12-1.116.amzn1.i686
    php56-fpm-5.6.12-1.116.amzn1.i686
    php56-bcmath-5.6.12-1.116.amzn1.i686
    php56-cli-5.6.12-1.116.amzn1.i686
    php56-dbg-5.6.12-1.116.amzn1.i686
    php56-dba-5.6.12-1.116.amzn1.i686
    php56-common-5.6.12-1.116.amzn1.i686
    php56-odbc-5.6.12-1.116.amzn1.i686
    php56-xml-5.6.12-1.116.amzn1.i686
    php56-imap-5.6.12-1.116.amzn1.i686
    php56-pdo-5.6.12-1.116.amzn1.i686
    php56-opcache-5.6.12-1.116.amzn1.i686
    php56-process-5.6.12-1.116.amzn1.i686

src:
    php56-5.6.12-1.116.amzn1.src

x86_64:
    php56-mbstring-5.6.12-1.116.amzn1.x86_64
    php56-devel-5.6.12-1.116.amzn1.x86_64
    php56-opcache-5.6.12-1.116.amzn1.x86_64
    php56-cli-5.6.12-1.116.amzn1.x86_64
    php56-snmp-5.6.12-1.116.amzn1.x86_64
    php56-dba-5.6.12-1.116.amzn1.x86_64
    php56-odbc-5.6.12-1.116.amzn1.x86_64
    php56-mysqlnd-5.6.12-1.116.amzn1.x86_64
    php56-recode-5.6.12-1.116.amzn1.x86_64
    php56-fpm-5.6.12-1.116.amzn1.x86_64
    php56-enchant-5.6.12-1.116.amzn1.x86_64
    php56-debuginfo-5.6.12-1.116.amzn1.x86_64
    php56-gmp-5.6.12-1.116.amzn1.x86_64
    php56-xml-5.6.12-1.116.amzn1.x86_64
    php56-common-5.6.12-1.116.amzn1.x86_64
    php56-pdo-5.6.12-1.116.amzn1.x86_64
    php56-embedded-5.6.12-1.116.amzn1.x86_64
    php56-tidy-5.6.12-1.116.amzn1.x86_64
    php56-imap-5.6.12-1.116.amzn1.x86_64
    php56-intl-5.6.12-1.116.amzn1.x86_64
    php56-bcmath-5.6.12-1.116.amzn1.x86_64
    php56-xmlrpc-5.6.12-1.116.amzn1.x86_64
    php56-pgsql-5.6.12-1.116.amzn1.x86_64
    php56-process-5.6.12-1.116.amzn1.x86_64
    php56-5.6.12-1.116.amzn1.x86_64
    php56-soap-5.6.12-1.116.amzn1.x86_64
    php56-pspell-5.6.12-1.116.amzn1.x86_64
    php56-dbg-5.6.12-1.116.amzn1.x86_64
    php56-mcrypt-5.6.12-1.116.amzn1.x86_64
    php56-ldap-5.6.12-1.116.amzn1.x86_64
    php56-mssql-5.6.12-1.116.amzn1.x86_64
    php56-gd-5.6.12-1.116.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2015-585.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Use-after-free

EUVDB-ID: #VU40517

Risk: Medium

CVSSv3.1: 6.7 [AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:U/RC:C]

CVE-ID: CVE-2015-6832

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing crafted serialized data that triggers misuse of an array field. &lt;a href=&quot;http://cwe.mitre.org/data/definitions/416. A remote attackers can execute arbitrary code.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

Mitigation

Update the affected packages:

i686:
    php56-mbstring-5.6.12-1.116.amzn1.i686
    php56-ldap-5.6.12-1.116.amzn1.i686
    php56-mysqlnd-5.6.12-1.116.amzn1.i686
    php56-soap-5.6.12-1.116.amzn1.i686
    php56-devel-5.6.12-1.116.amzn1.i686
    php56-recode-5.6.12-1.116.amzn1.i686
    php56-snmp-5.6.12-1.116.amzn1.i686
    php56-mssql-5.6.12-1.116.amzn1.i686
    php56-tidy-5.6.12-1.116.amzn1.i686
    php56-intl-5.6.12-1.116.amzn1.i686
    php56-5.6.12-1.116.amzn1.i686
    php56-pspell-5.6.12-1.116.amzn1.i686
    php56-embedded-5.6.12-1.116.amzn1.i686
    php56-gd-5.6.12-1.116.amzn1.i686
    php56-mcrypt-5.6.12-1.116.amzn1.i686
    php56-pgsql-5.6.12-1.116.amzn1.i686
    php56-debuginfo-5.6.12-1.116.amzn1.i686
    php56-enchant-5.6.12-1.116.amzn1.i686
    php56-gmp-5.6.12-1.116.amzn1.i686
    php56-xmlrpc-5.6.12-1.116.amzn1.i686
    php56-fpm-5.6.12-1.116.amzn1.i686
    php56-bcmath-5.6.12-1.116.amzn1.i686
    php56-cli-5.6.12-1.116.amzn1.i686
    php56-dbg-5.6.12-1.116.amzn1.i686
    php56-dba-5.6.12-1.116.amzn1.i686
    php56-common-5.6.12-1.116.amzn1.i686
    php56-odbc-5.6.12-1.116.amzn1.i686
    php56-xml-5.6.12-1.116.amzn1.i686
    php56-imap-5.6.12-1.116.amzn1.i686
    php56-pdo-5.6.12-1.116.amzn1.i686
    php56-opcache-5.6.12-1.116.amzn1.i686
    php56-process-5.6.12-1.116.amzn1.i686

src:
    php56-5.6.12-1.116.amzn1.src

x86_64:
    php56-mbstring-5.6.12-1.116.amzn1.x86_64
    php56-devel-5.6.12-1.116.amzn1.x86_64
    php56-opcache-5.6.12-1.116.amzn1.x86_64
    php56-cli-5.6.12-1.116.amzn1.x86_64
    php56-snmp-5.6.12-1.116.amzn1.x86_64
    php56-dba-5.6.12-1.116.amzn1.x86_64
    php56-odbc-5.6.12-1.116.amzn1.x86_64
    php56-mysqlnd-5.6.12-1.116.amzn1.x86_64
    php56-recode-5.6.12-1.116.amzn1.x86_64
    php56-fpm-5.6.12-1.116.amzn1.x86_64
    php56-enchant-5.6.12-1.116.amzn1.x86_64
    php56-debuginfo-5.6.12-1.116.amzn1.x86_64
    php56-gmp-5.6.12-1.116.amzn1.x86_64
    php56-xml-5.6.12-1.116.amzn1.x86_64
    php56-common-5.6.12-1.116.amzn1.x86_64
    php56-pdo-5.6.12-1.116.amzn1.x86_64
    php56-embedded-5.6.12-1.116.amzn1.x86_64
    php56-tidy-5.6.12-1.116.amzn1.x86_64
    php56-imap-5.6.12-1.116.amzn1.x86_64
    php56-intl-5.6.12-1.116.amzn1.x86_64
    php56-bcmath-5.6.12-1.116.amzn1.x86_64
    php56-xmlrpc-5.6.12-1.116.amzn1.x86_64
    php56-pgsql-5.6.12-1.116.amzn1.x86_64
    php56-process-5.6.12-1.116.amzn1.x86_64
    php56-5.6.12-1.116.amzn1.x86_64
    php56-soap-5.6.12-1.116.amzn1.x86_64
    php56-pspell-5.6.12-1.116.amzn1.x86_64
    php56-dbg-5.6.12-1.116.amzn1.x86_64
    php56-mcrypt-5.6.12-1.116.amzn1.x86_64
    php56-ldap-5.6.12-1.116.amzn1.x86_64
    php56-mssql-5.6.12-1.116.amzn1.x86_64
    php56-gd-5.6.12-1.116.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2015-585.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Path traversal

EUVDB-ID: #VU40516

Risk: Medium

CVSSv3.1: 6.9 [AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:U/RC:C]

CVE-ID: CVE-2015-6833

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12. A remote authenticated attacker can send a specially crafted HTTP request and remote attackers to write to arbitrary files via a . (dot dot) in a ZIP archive entry that is mishandled during an extractTo call.

Mitigation

Update the affected packages:

i686:
    php56-mbstring-5.6.12-1.116.amzn1.i686
    php56-ldap-5.6.12-1.116.amzn1.i686
    php56-mysqlnd-5.6.12-1.116.amzn1.i686
    php56-soap-5.6.12-1.116.amzn1.i686
    php56-devel-5.6.12-1.116.amzn1.i686
    php56-recode-5.6.12-1.116.amzn1.i686
    php56-snmp-5.6.12-1.116.amzn1.i686
    php56-mssql-5.6.12-1.116.amzn1.i686
    php56-tidy-5.6.12-1.116.amzn1.i686
    php56-intl-5.6.12-1.116.amzn1.i686
    php56-5.6.12-1.116.amzn1.i686
    php56-pspell-5.6.12-1.116.amzn1.i686
    php56-embedded-5.6.12-1.116.amzn1.i686
    php56-gd-5.6.12-1.116.amzn1.i686
    php56-mcrypt-5.6.12-1.116.amzn1.i686
    php56-pgsql-5.6.12-1.116.amzn1.i686
    php56-debuginfo-5.6.12-1.116.amzn1.i686
    php56-enchant-5.6.12-1.116.amzn1.i686
    php56-gmp-5.6.12-1.116.amzn1.i686
    php56-xmlrpc-5.6.12-1.116.amzn1.i686
    php56-fpm-5.6.12-1.116.amzn1.i686
    php56-bcmath-5.6.12-1.116.amzn1.i686
    php56-cli-5.6.12-1.116.amzn1.i686
    php56-dbg-5.6.12-1.116.amzn1.i686
    php56-dba-5.6.12-1.116.amzn1.i686
    php56-common-5.6.12-1.116.amzn1.i686
    php56-odbc-5.6.12-1.116.amzn1.i686
    php56-xml-5.6.12-1.116.amzn1.i686
    php56-imap-5.6.12-1.116.amzn1.i686
    php56-pdo-5.6.12-1.116.amzn1.i686
    php56-opcache-5.6.12-1.116.amzn1.i686
    php56-process-5.6.12-1.116.amzn1.i686

src:
    php56-5.6.12-1.116.amzn1.src

x86_64:
    php56-mbstring-5.6.12-1.116.amzn1.x86_64
    php56-devel-5.6.12-1.116.amzn1.x86_64
    php56-opcache-5.6.12-1.116.amzn1.x86_64
    php56-cli-5.6.12-1.116.amzn1.x86_64
    php56-snmp-5.6.12-1.116.amzn1.x86_64
    php56-dba-5.6.12-1.116.amzn1.x86_64
    php56-odbc-5.6.12-1.116.amzn1.x86_64
    php56-mysqlnd-5.6.12-1.116.amzn1.x86_64
    php56-recode-5.6.12-1.116.amzn1.x86_64
    php56-fpm-5.6.12-1.116.amzn1.x86_64
    php56-enchant-5.6.12-1.116.amzn1.x86_64
    php56-debuginfo-5.6.12-1.116.amzn1.x86_64
    php56-gmp-5.6.12-1.116.amzn1.x86_64
    php56-xml-5.6.12-1.116.amzn1.x86_64
    php56-common-5.6.12-1.116.amzn1.x86_64
    php56-pdo-5.6.12-1.116.amzn1.x86_64
    php56-embedded-5.6.12-1.116.amzn1.x86_64
    php56-tidy-5.6.12-1.116.amzn1.x86_64
    php56-imap-5.6.12-1.116.amzn1.x86_64
    php56-intl-5.6.12-1.116.amzn1.x86_64
    php56-bcmath-5.6.12-1.116.amzn1.x86_64
    php56-xmlrpc-5.6.12-1.116.amzn1.x86_64
    php56-pgsql-5.6.12-1.116.amzn1.x86_64
    php56-process-5.6.12-1.116.amzn1.x86_64
    php56-5.6.12-1.116.amzn1.x86_64
    php56-soap-5.6.12-1.116.amzn1.x86_64
    php56-pspell-5.6.12-1.116.amzn1.x86_64
    php56-dbg-5.6.12-1.116.amzn1.x86_64
    php56-mcrypt-5.6.12-1.116.amzn1.x86_64
    php56-ldap-5.6.12-1.116.amzn1.x86_64
    php56-mssql-5.6.12-1.116.amzn1.x86_64
    php56-gd-5.6.12-1.116.amzn1.x86_64

Vulnerable software versions

Amazon Linux AMI: All versions

External links

http://alas.aws.amazon.com/ALAS-2015-585.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###