php -- multiple vulnerabilities
Details
| VuXML ID | 85eb4e46-cf16-11e5-840f-485d605f4717 | 
| Discovery | 2016-02-04 | 
| Entry | 2016-02-09 | 
| Modified | 2016-03-13 | 
PHP reports:
	  
- Core:
	  
	    - Fixed bug #71039 (exec functions ignore length but look for NULL
	      termination).
- Fixed bug #71323 (Output of stream_get_meta_data can be
	      falsified by its input).
- Fixed bug #71459 (Integer overflow in iptcembed()).
 
- PCRE:
	  
	    - Upgraded bundled PCRE library to 8.38.(CVE-2015-8383,
	      CVE-2015-8386, CVE-2015-8387, CVE-2015-8389, CVE-2015-8390,
	      CVE-2015-8391, CVE-2015-8393, CVE-2015-8394)
 
- Phar:
	  
	    - Fixed bug #71354 (Heap corruption in tar/zip/phar parser).
- Fixed bug #71391 (NULL Pointer Dereference in
	      phar_tar_setupmetadata()).
- Fixed bug #71488 (Stack overflow when decompressing tar
	      archives). (CVE-2016-2554)
 
- WDDX:
	  
	    - Fixed bug #71335 (Type Confusion in WDDX Packet
	      Deserialization).
 
 
References
    Copyright © 2003-2005 Jacques Vidrine and contributors.
    
    Please see the source of this document for full copyright
    information.