-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : php5 Version : 5.6.40+dfsg-0+deb8u7 CVE ID : CVE-2019-11043
Emil Lerner, beched and d90pwn found a buffer underflow in php5-fpm, a Fast Process Manager for the PHP language, which can lead to remote code execution. Instances are vulnerable depending on the web server configuration, in particular PATH_INFO handling. For a full list of preconditions, check: https://github.com/neex/phuip-fpizdam For Debian 8 "Jessie", this problem has been fixed in version 5.6.40+dfsg-0+deb8u7. We recommend that you upgrade your php5 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEQic8GuN/xDR88HkSj/HLbo2JBZ8FAl20YgEACgkQj/HLbo2J BZ8u3ggAgHB+rJVnpGssmR85aY34EuMptcQUKkRt1s+rkuR5eBpk7JNtu6Pnp+z4 o1gOEQ8Z+0trRc2ydQu6BbTwXjZ1kLTZrg7E2zuGU7Lywnk3LihdMDljIKS8Yzi/ 9mOrh0QqHfydiaiH1QjlaMWAdRlqYq//PwNID8UoK+CEgvY9Jk/uWMemEX/0YBZU Fpb2miVy+R123bh5Y+P3TT+LcijlTPq4ZU7CDnz7oyRxfSubossU1eFpF6ok4iZh WB323BjNaf3E3OrmIyMXpMh8z6QV2G8eLG2a6ZZ1T3MSmpx2cq+lV+sg0PosiSZA 27B4PkxM7muLw49jq04DIrM1/+BWpA== =SuP9 -----END PGP SIGNATURE-----