-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 31 Aug 2018 22:28:51 -0400 Source: php5 Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-phpdbg php5-fpm libphp5-embed php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-imap php5-interbase php5-intl php5-ldap php5-mcrypt php5-readline php5-mysql php5-mysqlnd php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl Architecture: source all amd64 Version: 5.6.37+dfsg-0+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Debian PHP Maintainers <pkg-php-ma...@lists.alioth.debian.org> Changed-By: Roberto C. Sanchez <robe...@debian.org> Description: libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module) libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo libphp5-embed - HTML-embedded scripting language (Embedded SAPI library) php-pear - PEAR - PHP Extension and Application Repository php5 - server-side, HTML-embedded scripting language (metapackage) php5-cgi - server-side, HTML-embedded scripting language (CGI binary) php5-cli - command-line interpreter for the php5 scripting language php5-common - Common files for packages built from the php5 source php5-curl - CURL module for php5 php5-dbg - Debug symbols for PHP5 php5-dev - Files for PHP5 module development php5-enchant - Enchant module for php5 php5-fpm - server-side, HTML-embedded scripting language (FPM-CGI binary) php5-gd - GD module for php5 php5-gmp - GMP module for php5 php5-imap - IMAP module for php5 php5-interbase - interbase/firebird module for php5 php5-intl - internationalisation module for php5 php5-ldap - LDAP module for php5 php5-mcrypt - MCrypt module for php5 php5-mysql - MySQL module for php5 php5-mysqlnd - MySQL module for php5 (Native Driver) php5-odbc - ODBC module for php5 php5-pgsql - PostgreSQL module for php5 php5-phpdbg - server-side, HTML-embedded scripting language (PHPDBG binary) php5-pspell - pspell module for php5 php5-readline - Readline module for php5 php5-recode - recode module for php5 php5-snmp - SNMP module for php5 php5-sqlite - SQLite module for php5 php5-sybase - Sybase / MS SQL Server module for php5 php5-tidy - tidy module for php5 php5-xmlrpc - XML-RPC module for php5 php5-xsl - XSL module for php5 Closes: 890266 Changes: php5 (5.6.37+dfsg-0+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the LTS Team. * New upstream version 5.6.37+dfsg - [CVE-2018-14883] An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c. - [CVE-2018-14851] exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG file. * Drop patch for CVE-2017-7272. The patch breaks many applications that rely on undocumented behavior, was dropped by other distros, and the CVE was marked "ignore" by the security team. (Closes: #890266) Checksums-Sha1: 8bf1e30f50dc0b9a626554de9ad90bfde375499c 5096 php5_5.6.37+dfsg-0+deb8u1.dsc 00604a05f00fb65cdaa29a4ddf1690f7efc86d5d 19440222 php5_5.6.37+dfsg.orig.tar.gz a8ccbefd4687cf491a7dd12048b20c3ea3e1bb2f 132536 php5_5.6.37+dfsg-0+deb8u1.debian.tar.xz f8a20e6dd38d889057ca0e0e87efe8248f1c5ff3 1310 php5_5.6.37+dfsg-0+deb8u1_all.deb af90379dcafda635121d99c2faf3175e096589e1 265566 php-pear_5.6.37+dfsg-0+deb8u1_all.deb a4f894c22e90a34c3edd865f508eec6b6e039da7 743490 php5-common_5.6.37+dfsg-0+deb8u1_amd64.deb 8160e2bcf81ffc05c54df8672e0ada4e6225bbc8 2230058 libapache2-mod-php5_5.6.37+dfsg-0+deb8u1_amd64.deb dbbcb50841bd2ba39daf7e94a5ef4f9f9ee645af 2225522 libapache2-mod-php5filter_5.6.37+dfsg-0+deb8u1_amd64.deb 17460586d879bfbe409b94d87945008255fbe87c 4314742 php5-cgi_5.6.37+dfsg-0+deb8u1_amd64.deb 235d72678759ca995923e109290b22cf1f2e6fb3 2199246 php5-cli_5.6.37+dfsg-0+deb8u1_amd64.deb aea78adc88c9b13661cd5e54c013dd83bd17c009 2208424 php5-phpdbg_5.6.37+dfsg-0+deb8u1_amd64.deb da66cf940656ae4850f4baf9f4eeb8c4cdc584aa 2212452 php5-fpm_5.6.37+dfsg-0+deb8u1_amd64.deb e5587b8aef8ae00917a39f3929d5aab90f7bdf3f 2224324 libphp5-embed_5.6.37+dfsg-0+deb8u1_amd64.deb c1501f6704ce09ee20fa8829085acb3eab8656e1 357040 php5-dev_5.6.37+dfsg-0+deb8u1_amd64.deb 439b9ded4989a0bd10f6c1572728d010c1a610bf 51247992 php5-dbg_5.6.37+dfsg-0+deb8u1_amd64.deb e9eec664667d9d24213a2d9665c5a9b21f6b610b 27988 php5-curl_5.6.37+dfsg-0+deb8u1_amd64.deb f92c81e51ef59659ad20bf7bc4adc47f3f45adcd 9442 php5-enchant_5.6.37+dfsg-0+deb8u1_amd64.deb e31fe591470fd3c52ab287144e542251588b91fb 29236 php5-gd_5.6.37+dfsg-0+deb8u1_amd64.deb 64827f4e8cae46a76a0390219cd1e8ce375e693e 21700 php5-gmp_5.6.37+dfsg-0+deb8u1_amd64.deb d5eaf12de2e960cbb45dee7cb988754937c1f89a 31700 php5-imap_5.6.37+dfsg-0+deb8u1_amd64.deb df12a1cdc9b353f54b791e3418f4775a51db3f07 42876 php5-interbase_5.6.37+dfsg-0+deb8u1_amd64.deb 544b65ab60a2901df0f6d7cf918f56be1344167e 112504 php5-intl_5.6.37+dfsg-0+deb8u1_amd64.deb 6719afe7521e88c19b75dbb160fbb3e4784488ae 22468 php5-ldap_5.6.37+dfsg-0+deb8u1_amd64.deb 1f59cde020b4fb810520cf4c46a902e6832abf38 15608 php5-mcrypt_5.6.37+dfsg-0+deb8u1_amd64.deb c81d39777dbb053726d30fadbbf773ea94235376 12730 php5-readline_5.6.37+dfsg-0+deb8u1_amd64.deb c5dfcb0c9f70788b8695c57a0c3af41e05d2cb5e 65716 php5-mysql_5.6.37+dfsg-0+deb8u1_amd64.deb 084da075b2571bb69ec6af1e0620b8aa97f6be9c 142180 php5-mysqlnd_5.6.37+dfsg-0+deb8u1_amd64.deb 4e40f2d0c09909256621c082bfec25161d4e484c 32078 php5-odbc_5.6.37+dfsg-0+deb8u1_amd64.deb 7dd698f9d07004c5863e733b44ea318f0febec6f 59156 php5-pgsql_5.6.37+dfsg-0+deb8u1_amd64.deb c6c8b207696690cfdf4407da671e60c35931e914 8376 php5-pspell_5.6.37+dfsg-0+deb8u1_amd64.deb f78794999b385ce50b9742bf520c48211451b4bd 5766 php5-recode_5.6.37+dfsg-0+deb8u1_amd64.deb db393f16977b5d93a6a8ca8ffb2a207a14e17e1e 19772 php5-snmp_5.6.37+dfsg-0+deb8u1_amd64.deb 22a67e361288b2748ef2ed5e14ec52de6aa80f39 24796 php5-sqlite_5.6.37+dfsg-0+deb8u1_amd64.deb cbeff676b8e5b89cc21b75497d2d7b62f571c630 24816 php5-sybase_5.6.37+dfsg-0+deb8u1_amd64.deb 21317afb57f3b2b9de9a1d85dc53c1e5352656be 16984 php5-tidy_5.6.37+dfsg-0+deb8u1_amd64.deb d029793ffb410a9cd70ca10bcbb299b86ce74595 35786 php5-xmlrpc_5.6.37+dfsg-0+deb8u1_amd64.deb 5fa9031c729e405fb4cbc43b920fb2e0d5005897 14194 php5-xsl_5.6.37+dfsg-0+deb8u1_amd64.deb Checksums-Sha256: c939f24801ae73cb772ffbf51a9287bfa199dc290cdd9b34db83aea81dd097f2 5096 php5_5.6.37+dfsg-0+deb8u1.dsc e97b0a821af81a7027053b73c02183eb7b9148017c0b2191b5d44a70c6b12745 19440222 php5_5.6.37+dfsg.orig.tar.gz 18cdb5b1fa6d27be9dca11950d0c88c382deb9e1913edf678058f77339e54633 132536 php5_5.6.37+dfsg-0+deb8u1.debian.tar.xz dd8c9ad6dd6ebd355926526e5a332abd6742fa8b6e429294a584a54c29139b25 1310 php5_5.6.37+dfsg-0+deb8u1_all.deb eef46f3f05a5fd418fd54bda9011409914b4aee9ba26a0baa0126a5750ccd4db 265566 php-pear_5.6.37+dfsg-0+deb8u1_all.deb 9cf47a4385458547d5317b278f857deaa525e592ee443a6c2bfdcc92ac1e4114 743490 php5-common_5.6.37+dfsg-0+deb8u1_amd64.deb 54fd56f2a1607f4f3f6574bd80fff94468ef53d8648c32edf0f4992d7e168f91 2230058 libapache2-mod-php5_5.6.37+dfsg-0+deb8u1_amd64.deb 06eb745ba62e3f3dfc277d5107e8adf6140f719e543f11db34b8baacdbbdbbe3 2225522 libapache2-mod-php5filter_5.6.37+dfsg-0+deb8u1_amd64.deb ebd8cc9fdd5a3994390717fa997f06e47942a69b2cf01f29b8b9f0eed230e243 4314742 php5-cgi_5.6.37+dfsg-0+deb8u1_amd64.deb e077449cf14654be380048101924f4a8017886a813990ad0b1a1b3b7fa5df82a 2199246 php5-cli_5.6.37+dfsg-0+deb8u1_amd64.deb b7b241de652482a22708be1047051070129ff78d279e0c77c1cde9f92958f0c5 2208424 php5-phpdbg_5.6.37+dfsg-0+deb8u1_amd64.deb f7b8d76fb100c37d03a93d546920007450fe96c396e17307ab3a651c2ec6fffa 2212452 php5-fpm_5.6.37+dfsg-0+deb8u1_amd64.deb d3d3a784e7f92de7cf03f4d2bd0779d1104c748e5030fcd9006e7be76d05135d 2224324 libphp5-embed_5.6.37+dfsg-0+deb8u1_amd64.deb 52de6eac7ba585780399fa7924f4e7d8a05725b0a5a9a437466ec60f4256a6c3 357040 php5-dev_5.6.37+dfsg-0+deb8u1_amd64.deb c0e5864b6dad1fe1e249c1ae7fd02669e47c3883ecd5451b201e0f9966f0fdf2 51247992 php5-dbg_5.6.37+dfsg-0+deb8u1_amd64.deb bdafdcb1d4df684ef76af63dd9229fb3e71c21ec260166161d8ee78a08db9eb2 27988 php5-curl_5.6.37+dfsg-0+deb8u1_amd64.deb b83777081165b1ccc452b422d9cfa720b745bd67cdb2e7de45df3b908fcf656e 9442 php5-enchant_5.6.37+dfsg-0+deb8u1_amd64.deb 48273de6c993b29eb12a16808df76d9ea6fe1e74b0a31749975733b6ef590bab 29236 php5-gd_5.6.37+dfsg-0+deb8u1_amd64.deb 43b1724569178cfd34a946e12dbfddfcf1cfdf07c0d8c1eb4ac50cb5b59c843f 21700 php5-gmp_5.6.37+dfsg-0+deb8u1_amd64.deb 2bec9d2d322bf769600bd0d97fce28168f224bd460eaa3ed53798f53f5702d2a 31700 php5-imap_5.6.37+dfsg-0+deb8u1_amd64.deb 917e643b56ea55ab84ce7c8862ce03248fee9ecfc3120fbc07e14e3184c920c3 42876 php5-interbase_5.6.37+dfsg-0+deb8u1_amd64.deb 13ec678991ba1994ad3902555ad92cf398f0aa4ea0bd1350505e96718a7febb9 112504 php5-intl_5.6.37+dfsg-0+deb8u1_amd64.deb da3fcd0170a8a6f3f549139cff39612d16c1c10d5a4616c06bffeed10ed7be16 22468 php5-ldap_5.6.37+dfsg-0+deb8u1_amd64.deb d859c071769cb7ec9a46a8423bd63d60c34da1e9770261c6f923cf93e714cd72 15608 php5-mcrypt_5.6.37+dfsg-0+deb8u1_amd64.deb 1a41b5a718f3dae8bf747c4465849b7b3460078d9b1f244e3eaa1021a6014835 12730 php5-readline_5.6.37+dfsg-0+deb8u1_amd64.deb 67673623e5c23423480e1e9651ead2e40341007a2023c25230e86bf1516499f3 65716 php5-mysql_5.6.37+dfsg-0+deb8u1_amd64.deb de16778196bfcd9868af9c3fe8540418630669aa637fbb8ea81a4d46dae8548d 142180 php5-mysqlnd_5.6.37+dfsg-0+deb8u1_amd64.deb bd6113421cf277bd547b6c07559299bbaee036acb8d8f8d37729c014d563e203 32078 php5-odbc_5.6.37+dfsg-0+deb8u1_amd64.deb 9abd50afc8a0dcfa02de19d2f8aad609b8dd06e7d919921e9b12c9c9bd23624f 59156 php5-pgsql_5.6.37+dfsg-0+deb8u1_amd64.deb fc382355bae02ac46e924b225884ec41555be90272f22fe9578a516247f2e47a 8376 php5-pspell_5.6.37+dfsg-0+deb8u1_amd64.deb 738fdf3cf82417f2fb36d8b28577e1f1abb554f8a0909275c0a4537a18966a98 5766 php5-recode_5.6.37+dfsg-0+deb8u1_amd64.deb 7c0b7fa79fd919316ab8c814a2f23d0b7f8f80dc3246d490847e8e100f8566ef 19772 php5-snmp_5.6.37+dfsg-0+deb8u1_amd64.deb 6c25e8fc1d8855a62c4cc5a2d6e2f5e4c23be0ea7142f242df3be0321ba101ec 24796 php5-sqlite_5.6.37+dfsg-0+deb8u1_amd64.deb b735026cfb302d03a9caa7be92e4ca313fa8cac47a7df8c986651bc798de1885 24816 php5-sybase_5.6.37+dfsg-0+deb8u1_amd64.deb b3ddddc82eeea21e52c81763b7deccbae87a06f5b660865d11a1118d8fcd8671 16984 php5-tidy_5.6.37+dfsg-0+deb8u1_amd64.deb df68b75242660f48a07c9b37dc6d7143282db5c86d7df47ecf790145714158e0 35786 php5-xmlrpc_5.6.37+dfsg-0+deb8u1_amd64.deb 230088a417010449ec65e1cea796bdd195de59399314f83b1706e609f2871dfb 14194 php5-xsl_5.6.37+dfsg-0+deb8u1_amd64.deb Files: b6d2c1aca17f527cda9be5eeff27efec 5096 php optional php5_5.6.37+dfsg-0+deb8u1.dsc 18bbede7e1b07436a063d4f8fbff3655 19440222 php optional php5_5.6.37+dfsg.orig.tar.gz 08c727696b499993d8ac43c4631691cd 132536 php optional php5_5.6.37+dfsg-0+deb8u1.debian.tar.xz fa6d78e0041ae8cbf181a7d1f489e5bd 1310 php optional php5_5.6.37+dfsg-0+deb8u1_all.deb 8d0847fff872bb79c7fcfb3f8a6b4b4b 265566 php optional php-pear_5.6.37+dfsg-0+deb8u1_all.deb 42fa37ec2184b1f981c3d7a4cd628200 743490 php optional php5-common_5.6.37+dfsg-0+deb8u1_amd64.deb bf8b4beae4e193e114e9aa6993272f54 2230058 httpd optional libapache2-mod-php5_5.6.37+dfsg-0+deb8u1_amd64.deb c96204de9852ff48e05de423962f60ee 2225522 httpd extra libapache2-mod-php5filter_5.6.37+dfsg-0+deb8u1_amd64.deb 3e62dceb18bc368d00f8671440243ba1 4314742 php optional php5-cgi_5.6.37+dfsg-0+deb8u1_amd64.deb 03d794379d9c76575fb2af7badf70a79 2199246 php optional php5-cli_5.6.37+dfsg-0+deb8u1_amd64.deb 63012065cfbfe0fa357c7160d72ba953 2208424 php optional php5-phpdbg_5.6.37+dfsg-0+deb8u1_amd64.deb 3dd4a699ef0c128b777b880e3d9f4c29 2212452 php optional php5-fpm_5.6.37+dfsg-0+deb8u1_amd64.deb 4557befdc71576b7c630091ef0937ba7 2224324 php optional libphp5-embed_5.6.37+dfsg-0+deb8u1_amd64.deb 78ff3b8d99af4a53564912af76e0b2d1 357040 php optional php5-dev_5.6.37+dfsg-0+deb8u1_amd64.deb fdb6cf856b3c43ece8acde3e67e0df3f 51247992 debug extra php5-dbg_5.6.37+dfsg-0+deb8u1_amd64.deb 1ff41d6a7d0854bbd0ee5ff959373582 27988 php optional php5-curl_5.6.37+dfsg-0+deb8u1_amd64.deb 71f68eb32efc131b3e67f9babe28fe1c 9442 php optional php5-enchant_5.6.37+dfsg-0+deb8u1_amd64.deb afa7b6b6ed95c3c6ec9a39fa25659917 29236 php optional php5-gd_5.6.37+dfsg-0+deb8u1_amd64.deb a21596a50db1e6cf6c2d58a479ee23ec 21700 php optional php5-gmp_5.6.37+dfsg-0+deb8u1_amd64.deb fbc592e8f3fd2bb76b42a70cfc9689e8 31700 php optional php5-imap_5.6.37+dfsg-0+deb8u1_amd64.deb b1f9c3f74b28f48814608ece69efe59e 42876 php optional php5-interbase_5.6.37+dfsg-0+deb8u1_amd64.deb 4a696eba3f4d77c9d6f54b390aa233c7 112504 php optional php5-intl_5.6.37+dfsg-0+deb8u1_amd64.deb 72276c806c65f39d71a1b674da9466a4 22468 php optional php5-ldap_5.6.37+dfsg-0+deb8u1_amd64.deb ac4986262922ded8934300c326052a76 15608 php optional php5-mcrypt_5.6.37+dfsg-0+deb8u1_amd64.deb 02c8d88f06c6c3ed1875a94766844152 12730 php optional php5-readline_5.6.37+dfsg-0+deb8u1_amd64.deb 6bf559e3d8baef4f1172d09f04cec2be 65716 php optional php5-mysql_5.6.37+dfsg-0+deb8u1_amd64.deb f9b240c7ea63b9e83896a03ef4b912a4 142180 php extra php5-mysqlnd_5.6.37+dfsg-0+deb8u1_amd64.deb 0bc0765b31cb0e89bc2ab63cb9409f2a 32078 php optional php5-odbc_5.6.37+dfsg-0+deb8u1_amd64.deb 98faf5e02e0360e8234cbc1ddac066dd 59156 php optional php5-pgsql_5.6.37+dfsg-0+deb8u1_amd64.deb 8e7be023f3c769c7eb7656f41c251928 8376 php optional php5-pspell_5.6.37+dfsg-0+deb8u1_amd64.deb d7492dc6c7c4e10468555d23d7089d88 5766 php optional php5-recode_5.6.37+dfsg-0+deb8u1_amd64.deb 309a9819cfdf250bd8b3723f9db1b9e9 19772 php optional php5-snmp_5.6.37+dfsg-0+deb8u1_amd64.deb 8b48db3a957d3edcc6f86954659a1e71 24796 php optional php5-sqlite_5.6.37+dfsg-0+deb8u1_amd64.deb 9cfcadfa9c365f8d6b4fbd951e15e494 24816 php optional php5-sybase_5.6.37+dfsg-0+deb8u1_amd64.deb d3473b6a2b813584f6290b842dcf1e62 16984 php optional php5-tidy_5.6.37+dfsg-0+deb8u1_amd64.deb 4890d01069c2543a935ef85cf93e0249 35786 php optional php5-xmlrpc_5.6.37+dfsg-0+deb8u1_amd64.deb 4d2a4cd23e13b4d4c99dfb2000602afa 14194 php optional php5-xsl_5.6.37+dfsg-0+deb8u1_amd64.deb
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEz9ERzDttUsU/BH8iLNd4Xt2nsg8FAluKHA8ACgkQLNd4Xt2n sg9zww//eh8ytntiT0EYg4Vlm9iaTtUxK0MxG5tzkwOteAzJp0U2YQPgyDsbW+7a N5WVTwSuGs3AJlWcDc3Ex62mnW1Gc8eOlXYfINLaaj4wA3gOgW9R/QEAoRV+RZbT BAv4oe3UereZA1OZqIXQFYhh5rljorCsqTnezcXb1EbiJwda0HfLp55QsRKcLSZB qnWPiC04qQaZugLQVjrmKJI0w9d2wJAOrR3xdrtPFSE05W7obp6R08aSBA8pPn6h YbvgLqVmBfnc7iqyqesT4QiRu06oTkH8Hk3pKN+cPGO2gHqHL0dLRL+YVH71rUu+ niu6l/5PWrlqhw01fsBV2yMw+RffjHutOqsPeCA7yfx9kGzkp1fWL1NqndvF7F5U pesXkl4bB9fFQe7+ZRnHUp4fkCTELvV//fQrKv9fdGGGSMTOIO4rVaYZaNGbFFL2 JNPOkopi1ftQA/lIpC5i8CfBMK7EuxeNbS5fYWebLdgy9C2kHbRvtuSpE8BFRrOd FMuKaOaBO6V1YxErUGawgO84sEnXmKCyiWFBBQdpwmlKIpCeAm4T7zBrGxOoFj90 CH0oK6oIcqbQm5Ck6DPjkUnT91KY0HfBzr+/cS8kvJ96IuCjtBeznb/q8xhV5P6u yKsQKR+9A2fxy7if326OLCbs9DrCOMbV/NjkT5dqM5hvYAZSxyE= =Tk+2 -----END PGP SIGNATURE-----