{"id":"USN-2501-1","summary":"php5 vulnerabilities","details":"Stefan Esser discovered that PHP incorrectly handled unserializing objects.\nA remote attacker could use this issue to cause PHP to crash, resulting in\na denial of service, or possibly execute arbitrary code. (CVE-2014-8142,\nCVE-2015-0231)\n\nBrian Carpenter discovered that the PHP CGI component incorrectly handled\ninvalid files. A local attacker could use this issue to obtain sensitive\ninformation, or possibly execute arbitrary code. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-9427)\n\nIt was discovered that PHP incorrectly handled certain pascal strings in\nthe fileinfo extension. A remote attacker could possibly use this issue to\ncause PHP to crash, resulting in a denial of service. This issue only\naffected Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-9652)\n\nAlex Eubanks discovered that PHP incorrectly handled EXIF data in JPEG\nimages. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2015-0232)\n\nIt was discovered that the PHP opcache component incorrectly handled\nmemory. A remote attacker could possibly use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10.\n(CVE-2015-1351)\n\nIt was discovered that the PHP PostgreSQL database extension incorrectly\nhandled certain pointers. A remote attacker could possibly use this issue\nto cause PHP to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. This issue only affected Ubuntu 14.04 LTS and\nUbuntu 14.10. (CVE-2015-1352)\n","modified":"2026-04-22T09:08:18.321791Z","published":"2015-02-17T18:14:16Z","related":["UBUNTU-CVE-2014-8142","UBUNTU-CVE-2014-9427","UBUNTU-CVE-2014-9652","UBUNTU-CVE-2015-0231","UBUNTU-CVE-2015-0232","UBUNTU-CVE-2015-1351","UBUNTU-CVE-2015-1352"],"upstream":["CVE-2014-8142","CVE-2014-9427","CVE-2014-9652","CVE-2015-0231","CVE-2015-0232","CVE-2015-1351","CVE-2015-1352","UBUNTU-CVE-2014-8142","UBUNTU-CVE-2014-9427","UBUNTU-CVE-2014-9652","UBUNTU-CVE-2015-0231","UBUNTU-CVE-2015-0232","UBUNTU-CVE-2015-1351","UBUNTU-CVE-2015-1352"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-2501-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-8142"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-9427"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-9652"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-0231"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-0232"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-1351"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-1352"}],"affected":[{"package":{"name":"php5","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/php5@5.5.9+dfsg-1ubuntu4.6?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.5.9+dfsg-1ubuntu4.6"}]}],"versions":["5.5.3+dfsg-1ubuntu2","5.5.3+dfsg-1ubuntu3","5.5.6+dfsg-1ubuntu1","5.5.6+dfsg-1ubuntu2","5.5.8+dfsg-2ubuntu1","5.5.9+dfsg-1ubuntu1","5.5.9+dfsg-1ubuntu2","5.5.9+dfsg-1ubuntu3","5.5.9+dfsg-1ubuntu4","5.5.9+dfsg-1ubuntu4.1","5.5.9+dfsg-1ubuntu4.2","5.5.9+dfsg-1ubuntu4.3","5.5.9+dfsg-1ubuntu4.4","5.5.9+dfsg-1ubuntu4.5"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"libapache2-mod-php5"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"libapache2-mod-php5filter"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"libphp5-embed"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php-pear"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-cgi"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-cli"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-common"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-curl"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-enchant"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-fpm"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-gd"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-gmp"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-intl"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-ldap"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-mysql"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-mysqlnd"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-odbc"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-pgsql"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-pspell"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-readline"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-recode"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-snmp"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-sqlite"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-sybase"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-tidy"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-xmlrpc"},{"binary_version":"5.5.9+dfsg-1ubuntu4.6","binary_name":"php5-xsl"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2501-1.json","cves_map":{"cves":[{"severity":[{"score":"low","type":"Ubuntu"}],"id":"CVE-2014-8142"},{"severity":[{"score":"low","type":"Ubuntu"}],"id":"CVE-2014-9427"},{"severity":[{"score":"low","type":"Ubuntu"}],"id":"CVE-2014-9652"},{"severity":[{"score":"low","type":"Ubuntu"}],"id":"CVE-2015-0231"},{"severity":[{"score":"medium","type":"Ubuntu"}],"id":"CVE-2015-0232"},{"severity":[{"score":"medium","type":"Ubuntu"}],"id":"CVE-2015-1351"},{"severity":[{"score":"medium","type":"Ubuntu"}],"id":"CVE-2015-1352"}],"ecosystem":"Ubuntu:14.04:LTS"}}}],"schema_version":"1.7.5"}