Bug 200779 - lang/php56: Use after free vulnerability
Summary: lang/php56: Use after free vulnerability
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Many People
Assignee: Jason Unovitch
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-06-11 02:33 UTC by Sevan Janiyan
Modified: 2015-12-22 08:31 UTC (History)
2 users (show)

See Also:
bugzilla: maintainer-feedback? (ale)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sevan Janiyan 2015-06-11 02:33:38 UTC
https://bugs.php.net/bug.php?id=69737
Comment 1 Jason Unovitch freebsd_committer freebsd_triage 2015-07-13 10:23:48 UTC
This is fixed and ready to closed based off the PHP changelog.

http://php.net/ChangeLog-5.php#5.6.11
PHP 5 ChangeLog
Version 5.6.11
10 Jul 2015
SPL:
Fixed bug #69737 (Segfault when SplMinHeap::compare produces fatal error).

Note that upstream removed the "security" tag from the upstream bug tracker.
Comment 2 Jason Unovitch freebsd_committer freebsd_triage 2015-07-13 10:28:00 UTC
(In reply to Jason Unovitch from comment #1)
A followup now that I looked... we shouldn't "close" until the security fixes from 5.6.11 are all documented.  I'll address the documenting the recent PHP security tonight and we'll call this 100% after the VuXML update has been put into ports.
Comment 3 Kubilay Kocak freebsd_committer freebsd_triage 2015-12-16 02:27:36 UTC
@Jason, is this now resolved? If so, please add comment with references. If not, mention what still needs to be done
Comment 4 commit-hook freebsd_committer freebsd_triage 2015-12-18 01:35:00 UTC
A commit references this bug:

Author: junovitch
Date: Fri Dec 18 01:34:02 UTC 2015
New revision: 403947
URL: https://svnweb.freebsd.org/changeset/ports/403947

Log:
  Add PHP 5.6 package name to an earlier PHP VuXML entry

  PR:		200779
  Security:	CVE-2015-5590
  Security:	CVE-2015-5589
  Security:	https://vuxml.FreeBSD.org/freebsd/8b1f53f3-2da5-11e5-86ff-14dae9d210b8.html

Changes:
  head/security/vuxml/vuln.xml
Comment 5 Jason Unovitch freebsd_committer freebsd_triage 2015-12-18 01:36:47 UTC
Somehow we missed adding the PHP 5.6 package names for the PHAR extention to an earlier entry.  That has now been fixed.

The other PHP bugs and cross reference to VuXML are listed below:

PHP Bug 69972 - https://vuxml.FreeBSD.org/freebsd/3d39e927-29a2-11e5-86ff-14dae9d210b8.html

PHP Bug 69970 - https://vuxml.FreeBSD.org/freebsd/af7fbd91-29a1-11e5-86ff-14dae9d210b8.html

PHP Bug 69768 - https://vuxml.FreeBSD.org/freebsd/5a1d5d74-29a0-11e5-86ff-14dae9d210b8.html

PHP Bug 69669 - https://vuxml.FreeBSD.org/freebsd/36bd352d-299b-11e5-86ff-14dae9d210b8.html