{"id":"MGASA-2014-0162","summary":"Updated php packages fix security vulnerabilities","details":"Updated php packages fix security vulnerabilities:\n\nIt was discovered that the file utility contains a flaw in the handling of\n\"indirect\" magic rules in the libmagic library, which leads to an infinite\nrecursion when trying to determine the file type of certain files\n(CVE-2014-1943).\n\nA flaw was found in the way the file utility determined the type of Portable\nExecutable (PE) format files, the executable format used on Windows. A\nmalicious PE file could cause the file utility to crash or, potentially,\nexecute arbitrary code (CVE-2014-2270).\n\nPHP contains a bundled copy of the file utility's libmagic library, so it was\nvulnerable to these issues.  It has been updated to version 5.4.26, which\nfixes these issues and several other bugs.\n\nThis update also fixes a heap buffer over-read in DateInterval, which was\nfixed in PHP 5.4.24 (CVE-2013-6712).\n\nAlso, the timezonedb PHP PECL module has been updated to its newest version.\n\nAdditionally, php-apc has been rebuilt against the updated php package.\n","modified":"2026-04-16T01:47:42.744849419Z","published":"2014-04-04T12:08:18Z","upstream":["CVE-2013-6712","CVE-2014-1943","CVE-2014-2270"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0162.html"},{"type":"WEB","url":"http://www.php.net/ChangeLog-5.php#5.4.24"},{"type":"WEB","url":"http://www.php.net/ChangeLog-5.php#5.4.25"},{"type":"WEB","url":"http://www.php.net/ChangeLog-5.php#5.4.26"},{"type":"WEB","url":"http://pecl.php.net/package-changelog.php?package=timezonedb&release=2013.9"},{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2014-0092.html"},{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2014-0123.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=13017"}],"affected":[{"package":{"name":"php","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/php?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.26-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0162.json"}},{"package":{"name":"php-gd-bundled","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/php-gd-bundled?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.26-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0162.json"}},{"package":{"name":"php-apc","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/php-apc?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.14-7.6.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0162.json"}},{"package":{"name":"php-timezonedb","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/php-timezonedb?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2014.1-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0162.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}