Amazon Linux AMI : php55 (ALAS-2015-474)

high Nessus Plugin ID 81320

Synopsis

The remote Amazon Linux AMI host is missing a security update.

Description

sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not properly consider the mapping's length during processing of an invalid file that begins with a # character and lacks a newline character, which causes an out-of-bounds read and might (1) allow remote attackers to obtain sensitive information from php-cgi process memory by leveraging the ability to upload a .php file or (2) trigger unexpected code execution if a valid PHP script is present in memory locations adjacent to the mapping. (CVE-2014-9427)

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142 . (CVE-2015-0231)

The exif_process_unicode function in ext/exif/exif.c in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free and application crash) via crafted EXIF data in a JPEG image. (CVE-2015-0232)

Solution

Run 'yum update php55' to update your system.

See Also

https://alas.aws.amazon.com/ALAS-2015-474.html

Plugin Details

Severity: High

ID: 81320

File Name: ala_ALAS-2015-474.nasl

Version: 1.10

Type: local

Agent: unix

Published: 2/13/2015

Updated: 4/18/2018

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:php55-dba, p-cpe:/a:amazon:linux:php55-process, p-cpe:/a:amazon:linux:php55-recode, p-cpe:/a:amazon:linux:php55-snmp, p-cpe:/a:amazon:linux:php55-pspell, p-cpe:/a:amazon:linux:php55-pdo, p-cpe:/a:amazon:linux:php55-soap, p-cpe:/a:amazon:linux:php55-fpm, p-cpe:/a:amazon:linux:php55-opcache, p-cpe:/a:amazon:linux:php55-pgsql, p-cpe:/a:amazon:linux:php55-mysqlnd, p-cpe:/a:amazon:linux:php55-devel, p-cpe:/a:amazon:linux:php55-bcmath, p-cpe:/a:amazon:linux:php55, p-cpe:/a:amazon:linux:php55-gd, p-cpe:/a:amazon:linux:php55-gmp, p-cpe:/a:amazon:linux:php55-embedded, p-cpe:/a:amazon:linux:php55-mbstring, p-cpe:/a:amazon:linux:php55-odbc, p-cpe:/a:amazon:linux:php55-debuginfo, p-cpe:/a:amazon:linux:php55-tidy, p-cpe:/a:amazon:linux:php55-common, p-cpe:/a:amazon:linux:php55-xml, p-cpe:/a:amazon:linux:php55-ldap, p-cpe:/a:amazon:linux:php55-mssql, p-cpe:/a:amazon:linux:php55-xmlrpc, p-cpe:/a:amazon:linux:php55-enchant, p-cpe:/a:amazon:linux:php55-mcrypt, cpe:/o:amazon:linux, p-cpe:/a:amazon:linux:php55-cli, p-cpe:/a:amazon:linux:php55-imap, p-cpe:/a:amazon:linux:php55-intl

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Patch Publication Date: 2/11/2015

Reference Information

CVE: CVE-2014-9427, CVE-2015-0231, CVE-2015-0232

ALAS: 2015-474