Bug 882992 (CVE-2014-4049) - VUL-0: CVE-2014-4049: php5, php53: heap-based buffer overflow in DNS TXT record parsing
Summary: VUL-0: CVE-2014-4049: php5, php53: heap-based buffer overflow in DNS TXT reco...
Status: RESOLVED FIXED
Alias: CVE-2014-4049
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Deadline: 2014-06-24
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/99581/
Whiteboard: maint:released:sle11-sp2:57938 maint:...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-06-17 10:48 UTC by Johannes Segitz
Modified: 2020-05-18 11:53 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-06-17 10:48:20 UTC
Stefan Esser pointed out that the following commit fixes a heap-based buffer overflow in DNS TXT record parsing:

https://github.com/php/php-src/commit/b34d7849ed90ced9345f8ea1c59bc8d101c18468

A malicious server or man-in-the-middle attacker could possibly use this flaw to execute arbitrary code as the PHP interpreter if a PHP application uses dns_get_record() to perform a DNS query.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1108447
http://www.debian.org/security/2014/dsa-2961
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=751364
http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-4049.html
Comment 2 Swamp Workflow Management 2014-06-17 10:52:22 UTC
An update workflow for this issue was started.
This issue was rated as important.
Please submit fixed packages until 2014-06-24.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/57886
Comment 4 Petr Gajdos 2014-06-17 15:02:02 UTC
openSUSE: mr#237864
Comment 6 Bernhard Wiedemann 2014-06-17 16:00:57 UTC
This is an autogenerated message for OBS integration:
This bug (882992) was mentioned in
https://build.opensuse.org/request/show/237892 Factory / php5
Comment 7 Petr Gajdos 2014-06-17 16:03:23 UTC
submitted everywhere.
Comment 12 Swamp Workflow Management 2014-06-25 08:04:22 UTC
openSUSE-SU-2014:0841-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 882992
CVE References: CVE-2014-4049
Sources used:
openSUSE 13.1 (src):    php5-5.4.20-12.1
openSUSE 12.3 (src):    php5-5.3.17-3.16.1
Comment 14 Swamp Workflow Management 2014-07-03 18:50:44 UTC
Update released for: apache2-mod_php53, php53, php53-bcmath, php53-bz2, php53-calendar, php53-ctype, php53-curl, php53-dba, php53-debuginfo, php53-debugsource, php53-devel, php53-dom, php53-enchant, php53-exif, php53-fastcgi, php53-fileinfo, php53-fpm, php53-ftp, php53-gd, php53-gettext, php53-gmp, php53-iconv, php53-imap, php53-intl, php53-json, php53-ldap, php53-mbstring, php53-mcrypt, php53-mysql, php53-odbc, php53-openssl, php53-pcntl, php53-pdo, php53-pear, php53-pgsql, php53-phar, php53-posix, php53-pspell, php53-readline, php53-shmop, php53-snmp, php53-soap, php53-sockets, php53-sqlite, php53-suhosin, php53-sysvmsg, php53-sysvsem, php53-sysvshm, php53-tidy, php53-tokenizer, php53-wddx, php53-xmlreader, php53-xmlrpc, php53-xmlwriter, php53-xsl, php53-zip, php53-zlib
Products:
SLE-DEBUGINFO 11-SP2 (i386, s390x, x86_64)
SLE-SERVER 11-SP2-LTSS (i386, s390x, x86_64)
Comment 15 Swamp Workflow Management 2014-07-03 18:56:25 UTC
Update released for: apache2-mod_php5, php5, php5-bcmath, php5-bz2, php5-calendar, php5-ctype, php5-curl, php5-dba, php5-dbase, php5-debuginfo, php5-debugsource, php5-devel, php5-dom, php5-exif, php5-fastcgi, php5-ftp, php5-gd, php5-gettext, php5-gmp, php5-hash, php5-iconv, php5-imap, php5-json, php5-ldap, php5-mbstring, php5-mcrypt, php5-mysql, php5-ncurses, php5-odbc, php5-openssl, php5-pcntl, php5-pdo, php5-pear, php5-pgsql, php5-posix, php5-pspell, php5-readline, php5-shmop, php5-snmp, php5-soap, php5-sockets, php5-sqlite, php5-suhosin, php5-sysvmsg, php5-sysvsem, php5-sysvshm, php5-tidy, php5-tokenizer, php5-wddx, php5-xmlreader, php5-xmlrpc, php5-xmlwriter, php5-xsl, php5-zip, php5-zlib
Products:
SLE-DEBUGINFO 11-SP2 (i386, s390x, x86_64)
SLE-SERVER 11-SP2-LTSS (i386, s390x, x86_64)
Comment 16 Swamp Workflow Management 2014-07-03 19:57:42 UTC
Update released for: apache2-mod_php53, php53, php53-bcmath, php53-bz2, php53-calendar, php53-ctype, php53-curl, php53-dba, php53-debuginfo, php53-debugsource, php53-devel, php53-dom, php53-enchant, php53-exif, php53-fastcgi, php53-fileinfo, php53-fpm, php53-ftp, php53-gd, php53-gettext, php53-gmp, php53-iconv, php53-imap, php53-intl, php53-json, php53-ldap, php53-mbstring, php53-mcrypt, php53-mysql, php53-odbc, php53-openssl, php53-pcntl, php53-pdo, php53-pear, php53-pgsql, php53-phar, php53-posix, php53-pspell, php53-readline, php53-shmop, php53-snmp, php53-soap, php53-sockets, php53-sqlite, php53-suhosin, php53-sysvmsg, php53-sysvsem, php53-sysvshm, php53-tidy, php53-tokenizer, php53-wddx, php53-xmlreader, php53-xmlrpc, php53-xmlwriter, php53-xsl, php53-zip, php53-zlib
Products:
SLE-DEBUGINFO 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-SDK 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP3 (i386, x86_64)
Comment 17 Swamp Workflow Management 2014-07-03 22:04:40 UTC
SUSE-SU-2014:0868-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 868624,882992
CVE References: CVE-2014-2497,CVE-2014-4049
Sources used:
SUSE Linux Enterprise Server 11 SP2 LTSS (src):    php5-5.2.14-0.7.30.54.1
Comment 18 Swamp Workflow Management 2014-07-03 23:05:05 UTC
SUSE-SU-2014:0869-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 868624,880904,880905,882992
CVE References: CVE-2014-0237,CVE-2014-0238,CVE-2014-2497,CVE-2014-4049
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    php53-5.3.17-0.23.5
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    php53-5.3.17-0.23.5
SUSE Linux Enterprise Server 11 SP3 (src):    php53-5.3.17-0.23.5
SUSE Linux Enterprise Server 11 SP2 LTSS (src):    php53-5.3.8-0.45.1
Comment 19 Swamp Workflow Management 2014-07-04 16:04:21 UTC
Update released for: apache2-mod_php5, php5, php5-bcmath, php5-bz2, php5-calendar, php5-ctype, php5-curl, php5-dba, php5-dbase, php5-debuginfo, php5-devel, php5-dom, php5-exif, php5-fastcgi, php5-ftp, php5-gd, php5-gettext, php5-gmp, php5-hash, php5-iconv, php5-imap, php5-json, php5-ldap, php5-mbstring, php5-mcrypt, php5-mhash, php5-mysql, php5-ncurses, php5-odbc, php5-openssl, php5-pcntl, php5-pdo, php5-pear, php5-pgsql, php5-posix, php5-pspell, php5-readline, php5-shmop, php5-snmp, php5-soap, php5-sockets, php5-sqlite, php5-suhosin, php5-sysvmsg, php5-sysvsem, php5-sysvshm, php5-tidy, php5-tokenizer, php5-wddx, php5-xmlreader, php5-xmlrpc, php5-xmlwriter, php5-xsl, php5-zip, php5-zlib
Products:
SLE-DEBUGINFO 10-SP3-TERADATA (x86_64)
SLE-SERVER 10-SP3-TERADATA (x86_64)
Comment 20 Swamp Workflow Management 2014-07-04 19:54:03 UTC
Update released for: apache2-mod_php5, php5, php5-bcmath, php5-bz2, php5-calendar, php5-ctype, php5-curl, php5-dba, php5-dbase, php5-debuginfo, php5-devel, php5-dom, php5-exif, php5-fastcgi, php5-ftp, php5-gd, php5-gettext, php5-gmp, php5-hash, php5-iconv, php5-imap, php5-json, php5-ldap, php5-mbstring, php5-mcrypt, php5-mhash, php5-mysql, php5-ncurses, php5-odbc, php5-openssl, php5-pcntl, php5-pdo, php5-pear, php5-pgsql, php5-posix, php5-pspell, php5-readline, php5-shmop, php5-snmp, php5-soap, php5-sockets, php5-sqlite, php5-suhosin, php5-sysvmsg, php5-sysvsem, php5-sysvshm, php5-tidy, php5-tokenizer, php5-wddx, php5-xmlreader, php5-xmlrpc, php5-xmlwriter, php5-xsl, php5-zip, php5-zlib
Products:
SLE-DEBUGINFO 10-SP3 (i386, s390x, x86_64)
SLE-SERVER 10-SP3-LTSS (i386, s390x, x86_64)
Comment 21 Swamp Workflow Management 2014-07-04 20:50:34 UTC
Update released for: apache2-mod_php5, php5, php5-bcmath, php5-bz2, php5-calendar, php5-ctype, php5-curl, php5-dba, php5-dbase, php5-debuginfo, php5-devel, php5-dom, php5-exif, php5-fastcgi, php5-ftp, php5-gd, php5-gettext, php5-gmp, php5-hash, php5-iconv, php5-imap, php5-json, php5-ldap, php5-mbstring, php5-mcrypt, php5-mhash, php5-mysql, php5-ncurses, php5-odbc, php5-openssl, php5-pcntl, php5-pdo, php5-pear, php5-pgsql, php5-posix, php5-pspell, php5-readline, php5-shmop, php5-snmp, php5-soap, php5-sockets, php5-sqlite, php5-suhosin, php5-sysvmsg, php5-sysvsem, php5-sysvshm, php5-tidy, php5-tokenizer, php5-wddx, php5-xmlreader, php5-xmlrpc, php5-xmlwriter, php5-xsl, php5-zip, php5-zlib
Products:
SLE-DEBUGINFO 10-SP4 (i386, s390x, x86_64)
SLE-SERVER 10-SP4-LTSS (i386, s390x, x86_64)
Comment 22 Swamp Workflow Management 2014-07-05 00:05:53 UTC
SUSE-SU-2014:0873-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 837746,854880,868624,882992
CVE References: CVE-2013-4248,CVE-2013-6420,CVE-2014-2497,CVE-2014-4049
Sources used:
SUSE Linux Enterprise Server 10 SP4 LTSS (src):    php5-5.2.14-0.48.1
SUSE Linux Enterprise Server 10 SP3 LTSS (src):    php5-5.2.14-0.48.1
Comment 23 Swamp Workflow Management 2014-07-07 12:04:23 UTC
Update released for: apache2-mod_php5, php5, php5-bcmath, php5-bz2, php5-calendar, php5-ctype, php5-curl, php5-dba, php5-dbase, php5-debuginfo, php5-debugsource, php5-devel, php5-dom, php5-exif, php5-fastcgi, php5-ftp, php5-gd, php5-gettext, php5-gmp, php5-hash, php5-iconv, php5-imap, php5-json, php5-ldap, php5-mbstring, php5-mcrypt, php5-mysql, php5-ncurses, php5-odbc, php5-openssl, php5-pcntl, php5-pdo, php5-pear, php5-pgsql, php5-posix, php5-pspell, php5-readline, php5-shmop, php5-snmp, php5-soap, php5-sockets, php5-sqlite, php5-suhosin, php5-sysvmsg, php5-sysvsem, php5-sysvshm, php5-tidy, php5-tokenizer, php5-wddx, php5-xmlreader, php5-xmlrpc, php5-xmlwriter, php5-xsl, php5-zip, php5-zlib
Products:
SLE-DEBUGINFO 11-SP1-TERADATA (x86_64)
SLE-SERVER 11-SP1-TERADATA (x86_64)
Comment 24 Swamp Workflow Management 2014-07-07 13:50:57 UTC
Update released for: apache2-mod_php5, php5, php5-bcmath, php5-bz2, php5-calendar, php5-ctype, php5-curl, php5-dba, php5-dbase, php5-debuginfo, php5-debugsource, php5-devel, php5-dom, php5-exif, php5-fastcgi, php5-ftp, php5-gd, php5-gettext, php5-gmp, php5-hash, php5-iconv, php5-imap, php5-json, php5-ldap, php5-mbstring, php5-mcrypt, php5-mysql, php5-ncurses, php5-odbc, php5-openssl, php5-pcntl, php5-pdo, php5-pear, php5-pgsql, php5-posix, php5-pspell, php5-readline, php5-shmop, php5-snmp, php5-soap, php5-sockets, php5-sqlite, php5-suhosin, php5-sysvmsg, php5-sysvsem, php5-sysvshm, php5-tidy, php5-tokenizer, php5-wddx, php5-xmlreader, php5-xmlrpc, php5-xmlwriter, php5-xsl, php5-zip, php5-zlib
Products:
SLE-DEBUGINFO 11-SP1 (i386, s390x, x86_64)
SLE-SERVER 11-SP1-LTSS (i386, s390x, x86_64)
Comment 25 Marcus Meissner 2014-07-07 15:30:05 UTC
released
Comment 26 Swamp Workflow Management 2014-07-07 17:05:29 UTC
SUSE-SU-2014:0873-2: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 837746,854880,868624,882992
CVE References: CVE-2013-4248,CVE-2013-6420,CVE-2014-2497,CVE-2014-4049
Sources used:
SUSE Linux Enterprise Server 11 SP1 LTSS (src):    php5-5.2.14-0.7.30.54.1
Comment 27 Swamp Workflow Management 2014-07-30 18:44:26 UTC
openSUSE-SU-2014:0942-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 882992
CVE References: CVE-2014-4049
Sources used:
openSUSE 11.4 (src):    php5-5.3.5-367.1