{"id":"MGASA-2014-0163","summary":"Updated php packages fix security vulnerabilities","details":"Updated php packages fix security vulnerabilities:\n\nIt was discovered that the file utility contains a flaw in the handling of\n\"indirect\" magic rules in the libmagic library, which leads to an infinite\nrecursion when trying to determine the file type of certain files\n(CVE-2014-1943).\n\nA flaw was found in the way the file utility determined the type of Portable\nExecutable (PE) format files, the executable format used on Windows. A\nmalicious PE file could cause the file utility to crash or, potentially,\nexecute arbitrary code (CVE-2014-2270).\n\nPHP contains a bundled copy of the file utility's libmagic library, so it was\nvulnerable to these issues.  It has been updated to version 5.5.10, which\nfixes these issues and several other bugs.\n\nAlso, the jsonc, xdebug, and timezonedb PHP PECL modules have been updated to\ntheir newest versions.\n\nAdditionally, php-apc has been rebuilt against the updated php package.\n","modified":"2026-04-16T06:25:10.204791951Z","published":"2014-04-04T17:33:24Z","upstream":["CVE-2014-1943","CVE-2014-2270"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0163.html"},{"type":"WEB","url":"http://www.php.net/ChangeLog-5.php#5.5.9"},{"type":"WEB","url":"http://www.php.net/ChangeLog-5.php#5.5.10"},{"type":"WEB","url":"http://pecl.php.net/package-changelog.php?package=jsonc&release=1.3.4"},{"type":"WEB","url":"http://pecl.php.net/package-changelog.php?package=xdebug&release=2.2.4"},{"type":"WEB","url":"http://pecl.php.net/package-changelog.php?package=timezonedb&release=2013.9"},{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2014-0092.html"},{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2014-0123.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12842"}],"affected":[{"package":{"name":"php","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/php?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.5.10-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0163.json"}},{"package":{"name":"php-apc","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/php-apc?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.15-4.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0163.json"}},{"package":{"name":"php-timezonedb","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/php-timezonedb?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2014.1-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0163.json"}},{"package":{"name":"php-xdebug","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/php-xdebug?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.4-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0163.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}