Amazon Linux AMI : php70 (ALAS-2017-812)

critical Nessus Plugin ID 99039

Synopsis

The remote Amazon Linux AMI host is missing a security update.

Description

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image. (CVE-2016-10168)

In all versions of PHP 7, during the unserialization process, resizing the 'properties'; hash table of a serialized object may lead to use-after-free. A remote attacker may exploit this bug to gain arbitrary code execution. (CVE-2016-7479)

The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via crafted serialized data that is mishandled in a finish_nested_data call. (CVE-2016-10161)

Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch. (CVE-2016-10160)

The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an inapplicable class name in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call. (CVE-2016-10162)

It was found that the exif_convert_any_to_int() function in PHP was vulnerable to floating point exceptions when parsing tags in image files. A remote attacker with the ability to upload a malicious image could crash PHP, causing a Denial of Service. (CVE-2016-10158)

Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory consumption or application crash) via a truncated manifest entry in a PHAR archive.
(CVE-2016-10159)

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
(CVE-2016-10167)

Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.(CVE-2017-5340)

Solution

Run 'yum update php70' to update your system.

See Also

https://alas.aws.amazon.com/ALAS-2017-812.html

Plugin Details

Severity: Critical

ID: 99039

File Name: ala_ALAS-2017-812.nasl

Version: 3.2

Type: local

Agent: unix

Published: 3/30/2017

Updated: 4/18/2018

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:php70-enchant, p-cpe:/a:amazon:linux:php70-json, p-cpe:/a:amazon:linux:php70, p-cpe:/a:amazon:linux:php70-pdo, p-cpe:/a:amazon:linux:php70-pdo-dblib, p-cpe:/a:amazon:linux:php70-imap, p-cpe:/a:amazon:linux:php70-process, p-cpe:/a:amazon:linux:php70-zip, p-cpe:/a:amazon:linux:php70-soap, p-cpe:/a:amazon:linux:php70-devel, p-cpe:/a:amazon:linux:php70-bcmath, p-cpe:/a:amazon:linux:php70-opcache, p-cpe:/a:amazon:linux:php70-dba, p-cpe:/a:amazon:linux:php70-mcrypt, cpe:/o:amazon:linux, p-cpe:/a:amazon:linux:php70-xmlrpc, p-cpe:/a:amazon:linux:php70-common, p-cpe:/a:amazon:linux:php70-ldap, p-cpe:/a:amazon:linux:php70-pspell, p-cpe:/a:amazon:linux:php70-embedded, p-cpe:/a:amazon:linux:php70-gmp, p-cpe:/a:amazon:linux:php70-dbg, p-cpe:/a:amazon:linux:php70-xml, p-cpe:/a:amazon:linux:php70-pgsql, p-cpe:/a:amazon:linux:php70-recode, p-cpe:/a:amazon:linux:php70-snmp, p-cpe:/a:amazon:linux:php70-mysqlnd, p-cpe:/a:amazon:linux:php70-intl, p-cpe:/a:amazon:linux:php70-tidy, p-cpe:/a:amazon:linux:php70-gd, p-cpe:/a:amazon:linux:php70-debuginfo, p-cpe:/a:amazon:linux:php70-fpm, p-cpe:/a:amazon:linux:php70-mbstring, p-cpe:/a:amazon:linux:php70-odbc, p-cpe:/a:amazon:linux:php70-cli

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Patch Publication Date: 3/29/2017

Reference Information

CVE: CVE-2016-10158, CVE-2016-10159, CVE-2016-10160, CVE-2016-10161, CVE-2016-10162, CVE-2016-10167, CVE-2016-10168, CVE-2016-7479, CVE-2017-5340

ALAS: 2017-812