php-5.4.16-48.0.12.el7.AXS7
エラータID: AXSA:2025-10958:11
リリース日:
2025/10/15 Wednesday - 11:38
題名:
php-5.4.16-48.0.12.el7.AXS7
影響のあるチャネル:
Asianux Server 7 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- PHP が利用する Oniguruma には、ヒープベースのバッファオーバー
フローの問題があるため、リモートの攻撃者により、メモリ破壊を可能
とする脆弱性が存在します。(CVE-2017-9228)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2017-9228
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write occurs in bitset_set_range() during regular expression compilation due to an uninitialized variable from an incorrect state transition. An incorrect state transition in parse_char_class() could create an execution path that leaves a critical local variable uninitialized until it's used as an index, resulting in an out-of-bounds write memory corruption.
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write occurs in bitset_set_range() during regular expression compilation due to an uninitialized variable from an incorrect state transition. An incorrect state transition in parse_char_class() could create an execution path that leaves a critical local variable uninitialized until it's used as an index, resulting in an out-of-bounds write memory corruption.
追加情報:
N/A
ダウンロード:
SRPMS
- php-5.4.16-48.0.12.el7.AXS7.src.rpm not found
Asianux Server 7 for x86_64
- php-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: dea0cfc84470187a5a666f7b6a7e27af
SHA-256: 8e45d61bf6b0a20cb462124ce55793f362f3581be9a9c622252d55f3a56d2f54
Size: 1.36 MB - php-bcmath-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: 381553e2520238308716999e6fe4b659
SHA-256: cfdbc37fad1f1384122c39471284dfbedaee5948c0e22ac2bfd6a1b4261d963e
Size: 60.81 kB - php-cli-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: f1e9bfb509197f0a3f61605d30bbb1c2
SHA-256: 8265c4bdf3f5ea8c2bc62b2a6c9256f8f0feb640ea8df588570c407cfd46d728
Size: 2.75 MB - php-common-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: 191807b03da1850d6341acc9d5a62656
SHA-256: 78f80922d62c0781d5dfc4371c2052523334880e4f4c914027f23515baabf6b6
Size: 568.07 kB - php-gd-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: c0145ec7e0acbeb38942f6752b42a1bf
SHA-256: 884266f715908de769a2ef777a44a935e9dea2323f586f306d2d2c8809043921
Size: 130.68 kB - php-ldap-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: 233cdb5e514115f284cf684afe2a183f
SHA-256: 04e07cecc5950adb5ac7af954b37b3edc85c9ae756058b2462158780819908a7
Size: 55.78 kB - php-mbstring-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: 22a9b3b634b900f8cefb507a31991b21
SHA-256: 31ffac592938c1734ba253fba8fb06d062885fa291adf0eae67494650b914b2e
Size: 508.12 kB - php-mysql-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: bd16f2724e048d1aee3a61660f732967
SHA-256: feef3f922c8f13bc11dd67e143e926405ec5fa8afa67142efbea08b8e2ba1edc
Size: 104.41 kB - php-odbc-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: 231b87f6f8673ee551f509289f1b44e6
SHA-256: 664082283880e7e0479af44ca63ed27ab637c5ea02e8c191d7046b39d6e41c73
Size: 68.68 kB - php-pdo-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: ef9d3f9070a63bf41d8311696429b131
SHA-256: c13b97b662cc647f4dff494d952f3cbdc2b013102d69a6e49ffbaa88814e8856
Size: 102.01 kB - php-pgsql-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: 5c2a8bb2eb73c9de9525e6cd6e52b89c
SHA-256: d1b8092a3a45ce7c9d38050d25f566ab899e5d8971dbdbbbfb5faef6b0dd2414
Size: 91.00 kB - php-process-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: daacd119eb65ffb438d4656483235473
SHA-256: 8a92b728881ff598fd02bcaa4b11c6407397c8564f3a8aa94d1ee6be17c6ed3a
Size: 59.08 kB - php-recode-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: 3eea5bc85ecdbbb9a168b9a3c71aaa5a
SHA-256: 5da2bffbb209f1107baf841b097b555b1029a041d23b59697c7c751d416c2f58
Size: 41.73 kB - php-soap-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: 8a08a15bc46a282f6daeddcebddef59a
SHA-256: 39818ec43ad09cdb8b3fd8d70f25bbdd3e8e07a98395c39c3adc12c9753938d3
Size: 162.00 kB - php-xml-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: e8cd28a6eea9e0742303fdadde7029cf
SHA-256: de0fec22ef1eb08c41a0b59565e637b24683d0018b73db803856e50db35b935b
Size: 130.33 kB - php-xmlrpc-5.4.16-48.0.12.el7.AXS7.x86_64.rpm
MD5: c14ee8b37860f1e9534c840a73bf0888
SHA-256: a0c5b714f56d7a57b4dd151e4a45ac0097ccd1b15eea19eae384930ebe515c7f
Size: 71.37 kB