Vulnerability Name:

CVE-2018-10547 (CCN-142566)

Assigned:2018-04-26
Published:2018-04-26
Updated:2019-08-19
Summary:An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a request for a .phar file.
Note: this vulnerability exists because of an incomplete fix for CVE-2018-5712.
CVSS v3 Severity:6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
6.1 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.8 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2018-10547

Source: CCN
Type: PHP Web site
PHP 5 ChangeLog

Source: CONFIRM
Type: Patch, Vendor Advisory
http://php.net/ChangeLog-5.php

Source: CCN
Type: PHP Web site
PHP 7 ChangeLog

Source: CONFIRM
Type: Patch, Vendor Advisory
http://php.net/ChangeLog-7.php

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1040807

Source: REDHAT
Type: UNKNOWN
RHSA-2019:2519

Source: CONFIRM
Type: Issue Tracking, Patch, Vendor Advisory
https://bugs.php.net/bug.php?id=76129

Source: XF
Type: UNKNOWN
php-cve201810547-xss(142566)

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20180509 [SECURITY] [DLA 1373-1] php5 security update

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20180626 [SECURITY] [DLA 1397-1] php5 security update

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20180607-0003/

Source: UBUNTU
Type: Third Party Advisory
USN-3646-1

Source: UBUNTU
Type: Third Party Advisory
USN-3646-2

Source: DEBIAN
Type: Third Party Advisory
DSA-4240

Source: CCN
Type: IBM Security Bulletin 0713449 (API Connect)
API Connect Developer Portal is affected by multiple PHP vulnerabilities

Source: CCN
Type: IBM Security Bulletin 0719483 (Lotus Protector for Mail Security)
IBM Lotus Protector for Mail Security has released fixes in response to the public disclosed vulnerability from PHP

Source: CONFIRM
Type: Third Party Advisory
https://www.tenable.com/security/tns-2018-12

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2018-10547

Vulnerable Configuration:Configuration 1:
  • cpe:/a:php:php:*:*:*:*:*:*:*:* (Version < 5.6.36)
  • OR cpe:/a:php:php:*:*:*:*:*:*:*:* (Version >= 7.0.0 and < 7.0.30)
  • OR cpe:/a:php:php:*:*:*:*:*:*:*:* (Version >= 7.1.0 and < 7.1.17)
  • OR cpe:/a:php:php:*:*:*:*:*:*:*:* (Version >= 7.2.0 and < 7.2.5)

  • Configuration 2:
  • cpe:/o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

  • Configuration 3:
  • cpe:/o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/a:netapp:storage_automation_store:-:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:php:php:5:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:lotus_protector:2.8.1:*:*:*:mail_security:*:*:*
  • OR cpe:/a:ibm:lotus_protector:2.8.3:*:*:*:mail_security:*:*:*
  • OR cpe:/a:ibm:api_connect:5.0.8.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201810547
    V
    CVE-2018-10547
    2022-09-02
    oval:org.opensuse.security:def:10439
    P
    Security update for SDL2 (Important) (in QA)
    2022-01-12
    oval:org.opensuse.security:def:10710
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:10438
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:10372
    P
    Security update for aaa_base (Moderate)
    2021-12-03
    oval:org.opensuse.security:def:10371
    P
    Security update for the Linux Kernel (Important)
    2021-12-02
    oval:org.opensuse.security:def:32231
    P
    Security update for clamav (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:30157
    P
    Security update for webkit2gtk3 (Important)
    2021-12-01
    oval:org.opensuse.security:def:10170
    P
    Security update for qemu (Important)
    2021-11-04
    oval:org.opensuse.security:def:34583
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:10169
    P
    Security update for Salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:38669
    P
    Security update for MozillaFirefox, rust-cbindgen (Important)
    2021-10-18
    oval:org.opensuse.security:def:30246
    P
    Security update for gtk-vnc (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:35264
    P
    Security update for ntfs-3g_ntfsprogs (Important)
    2021-09-07
    oval:org.opensuse.security:def:10148
    P
    Security update for ffmpeg (Important)
    2021-09-02
    oval:org.opensuse.security:def:10147
    P
    Security update for xerces-c (Important)
    2021-09-02
    oval:org.opensuse.security:def:11120
    P
    Security update for libspf2 (Critical)
    2021-08-25
    oval:org.opensuse.security:def:33961
    P
    Security update for python-PyYAML (Important)
    2021-08-24
    oval:org.opensuse.security:def:10139
    P
    Security update for djvulibre (Important)
    2021-08-20
    oval:org.opensuse.security:def:10140
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:13988
    P
    ntp-4.2.8p8-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14314
    P
    libxerces-c-3_1-3.1.1-12.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13968
    P
    libudisks2-0-2.1.3-1.13 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14305
    P
    libvdpau1-1.1.1-6.73 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14234
    P
    libhogweed2-2.7.1-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14143
    P
    ghostscript-9.15-22.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14965
    P
    libXt6-1.1.4-3.57 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14056
    P
    wget-1.14-10.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14329
    P
    ntp-4.2.8p10-63.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13990
    P
    openslp-2.0.0-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14316
    P
    libxslt-tools-1.1.28-16.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13958
    P
    libspice-server1-0.12.7-6.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14259
    P
    libmusicbrainz4-2.1.5-27.79 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14236
    P
    libidn-tools-1.28-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14987
    P
    libevent-2_0-5-2.0.21-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14104
    P
    coreutils-8.25-12.8 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14967
    P
    libXv1-1.0.10-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14058
    P
    wpa_supplicant-2.2-14.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13960
    P
    libsrtp1-1.5.2-2.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14261
    P
    libneon27-0.30.0-3.64 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14122
    P
    dosfstools-3.0.26-6.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14989
    P
    libexif12-0.6.21-8.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14106
    P
    cpp48-4.8.5-30.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13966
    P
    libthai-data-0.1.25-4.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14303
    P
    libupsclient1-2.7.1-4.55 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14141
    P
    gdk-pixbuf-loader-rsvg-2.40.15-4.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14124
    P
    dracut-044-113.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14327
    P
    mozilla-nspr-32bit-4.13.1-18.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:38200
    P
    Security update for libcares2 (Important)
    2021-08-10
    oval:org.opensuse.security:def:33950
    P
    Security update for dbus-1 (Important)
    2021-08-02
    oval:org.opensuse.security:def:33949
    P
    Security update for qemu (Important)
    2021-07-28
    oval:org.opensuse.security:def:31228
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-07-21
    oval:org.opensuse.security:def:11099
    P
    Security update for fossil (Moderate)
    2021-07-17
    oval:org.opensuse.security:def:11098
    P
    Security update for claws-mail (Moderate)
    2021-07-16
    oval:org.opensuse.security:def:10685
    P
    Security update for the Linux Kernel (Important)
    2021-07-15
    oval:org.opensuse.security:def:10296
    P
    Security update for go1.15 (Important)
    2021-06-30
    oval:org.opensuse.security:def:38360
    P
    Security update for xorg-x11-libX11 (Important)
    2021-06-15
    oval:org.opensuse.security:def:10278
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:10277
    P
    Security update for spice-gtk (Moderate)
    2021-06-10
    oval:org.opensuse.security:def:11434
    P
    pcsc-ccid-1.4.14-1.45 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:124640
    P
    php5-devel-5.5.14-109.41.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36280
    P
    python-lxml-2.3.6-0.13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16634
    P
    php5-devel-5.5.14-109.41.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:124641
    P
    php7-devel-7.0.7-50.52.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36322
    P
    wireshark-1.10.13-0.2.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11412
    P
    libvorbis0-1.3.3-8.23 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16635
    P
    php7-devel-7.0.7-50.52.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:10263
    P
    Security update for ceph (Important)
    2021-06-02
    oval:org.opensuse.security:def:10262
    P
    Security update for curl (Moderate)
    2021-05-31
    oval:org.opensuse.security:def:34425
    P
    Security update for python36 (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:38198
    P
    Security update for kvm (Important)
    2021-04-23
    oval:org.opensuse.security:def:31141
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:39507
    P
    Security update for tar (Low)
    2021-03-29
    oval:org.opensuse.security:def:34045
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:32270
    P
    Security update for wpa_supplicant (Important)
    2021-03-09
    oval:org.opensuse.security:def:10216
    P
    Security update for wpa_supplicant (Important)
    2021-03-08
    oval:org.opensuse.security:def:10215
    P
    Security update for python-cryptography (Important)
    2021-03-03
    oval:org.opensuse.security:def:34641
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:10397
    P
    Security update for salt (Critical)
    2021-02-26
    oval:org.opensuse.security:def:38610
    P
    Security update for ImageMagick (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:10396
    P
    Security update for php7 (Important)
    2021-02-24
    oval:org.opensuse.security:def:30025
    P
    Security update for screen (Important)
    2021-02-17
    oval:org.opensuse.security:def:10297
    P
    Security update for go1.14 (Moderate)
    2021-01-26
    oval:org.opensuse.security:def:11121
    P
    Security update for viewvc (Moderate)
    2021-01-19
    oval:org.opensuse.security:def:38608
    P
    Security update for ImageMagick (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:34336
    P
    Security update for openssh (Moderate)
    2020-12-16
    oval:org.opensuse.security:def:29951
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:31084
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:35571
    P
    kdelibs3-3.5.10-23.27.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16948
    P
    php7-devel-7.0.7-50.85.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35642
    P
    sysstat-8.1.5-7.9.56 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35598
    P
    libpulse-browse0-0.9.21-1.5.26 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35532
    P
    cron-4.1-194.24.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:37965
    P
    libsrtp1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17771
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:38667
    P
    libexif12 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18719
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:10453
    P
    hplip-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26973
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27629
    P
    Security update for krb5
    2020-12-01
    oval:org.opensuse.security:def:17724
    P
    Security update for php5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:35174
    P
    Security update for kvm
    2020-12-01
    oval:org.opensuse.security:def:34798
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27778
    P
    Security update for krb5
    2020-12-01
    oval:org.opensuse.security:def:30992
    P
    Security update for jakarta-taglibs-standard (Important)
    2020-12-01
    oval:org.opensuse.security:def:28488
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31593
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29940
    P
    Security update for libksba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38300
    P
    libical1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27474
    P
    libproxy-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30647
    P
    Security update for xorg-x11-libxcb
    2020-12-01
    oval:org.opensuse.security:def:34754
    P
    Security update for MozillaFirefox, mozilla-nss, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:39467
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17597
    P
    Security update for the SUSE Linux Enterprise 12 kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:10576
    P
    nut-cgi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17990
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10447
    P
    gnome-settings-daemon-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30774
    P
    Security update for avahi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34796
    P
    Security update for ansible (Important)
    2020-12-01
    oval:org.opensuse.security:def:28195
    P
    Security update for libdb-4_5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31440
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:28311
    P
    Security update for openssl (Important)
    2020-12-01
    oval:org.opensuse.security:def:17802
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18745
    P
    Security update for php5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:37966
    P
    libssh2-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27101
    P
    cron on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30303
    P
    Security update for sudo (Important)
    2020-12-01
    oval:org.opensuse.security:def:38716
    P
    libproxy1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27673
    P
    Security update for Ruby On Rails 3.2 stack
    2020-12-01
    oval:org.opensuse.security:def:37967
    P
    libssh4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17781
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:35436
    P
    Security update for openvpn (Important)
    2020-12-01
    oval:org.opensuse.security:def:27842
    P
    Security update for nagios
    2020-12-01
    oval:org.opensuse.security:def:28503
    P
    Security update for openssh-openssl1 (Critical)
    2020-12-01
    oval:org.opensuse.security:def:26897
    P
    freeradius-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17595
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:34181
    P
    Security update for openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38358
    P
    libpython3_6m1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27527
    P
    openslp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18037
    P
    Security update for ghostscript (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39509
    P
    Security update for php5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:10591
    P
    python3-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30686
    P
    Security update for LibVNCServer (Critical)
    2020-12-01
    oval:org.opensuse.security:def:10460
    P
    lhasa-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30775
    P
    Security update for avahi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34880
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:38302
    P
    libidn-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28347
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31489
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28346
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:17838
    P
    Security update for php7 (Important)
    2020-12-01
    oval:org.opensuse.security:def:10448
    P
    gnome-shell-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37977
    P
    libusbmuxd4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27182
    P
    libexif on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30389
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:38755
    P
    mutt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29185
    P
    Security update for mysql (Important)
    2020-12-01
    oval:org.opensuse.security:def:10461
    P
    lib3ds-1-3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17812
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:35424
    P
    Security update for openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:10752
    P
    libjson-c-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18071
    P
    Security update for libcares2 (Low)
    2020-12-01
    oval:org.opensuse.security:def:35477
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:37968
    P
    libsystemd0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27970
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:38718
    P
    libpython2_7-1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28547
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:26898
    P
    freetype2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17629
    P
    Security update for net-snmp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34279
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38448
    P
    pigz on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27576
    P
    valgrind on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18049
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10610
    P
    xfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30705
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:27766
    P
    Security update for jasper
    2020-12-01
    oval:org.opensuse.security:def:17605
    P
    Security update for MozillaFirefox (Critical)
    2020-12-01
    oval:org.opensuse.security:def:35016
    P
    Security update for graphviz (Low)
    2020-12-01
    oval:org.opensuse.security:def:28400
    P
    Security update for spice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18047
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38827
    P
    xinetd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30786
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:17948
    P
    Security update for libtasn1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31528
    P
    Security update for ruby (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10774
    P
    libplist++-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38061
    P
    sblim-sfcb on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27239
    P
    man on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30543
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:34690
    P
    Security update for xorg-x11
    2020-12-01
    oval:org.opensuse.security:def:38783
    P
    python-libxml2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29221
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34784
    P
    Security update for OpenEXR (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10483
    P
    libapr1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17848
    P
    Security update for libtcnative-1-0 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35483
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10761
    P
    libmusicbrainz-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18709
    P
    Security update for librelp (Important)
    2020-12-01
    oval:org.opensuse.security:def:37979
    P
    libvirglrenderer0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28054
    P
    Security update for cyrus-imapd (Important)
    2020-12-01
    oval:org.opensuse.security:def:38757
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31387
    P
    Security update for openvpn-openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17714
    P
    Security update for ghostscript (Low)
    2020-12-01
    oval:org.opensuse.security:def:18081
    P
    Security update for xorg-x11-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26909
    P
    gpg2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27615
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:30749
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27767
    P
    Security update for IBM Java
    2020-12-01
    oval:org.opensuse.security:def:17639
    P
    Security update for jasper (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35117
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:38450
    P
    powerpc-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28449
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:18059
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:39465
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17587
    P
    Security update for php5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:30860
    P
    Security update for e2fsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17980
    P
    Security update for libquicktime (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31549
    P
    Security update for screen (Low)
    2020-12-01
    oval:org.opensuse.security:def:29939
    P
    Security update for libksba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27323
    P
    xalan-j2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30598
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34729
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38829
    P
    xorg-x11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10529
    P
    libpcscspy0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17958
    P
    Security update for spice (Important)
    2020-12-01
    oval:org.opensuse.security:def:18735
    P
    Security update for php7 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34785
    P
    Security update for OpenEXR (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38063
    P
    shim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28111
    P
    Security update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31384
    P
    Security update for openvpn (Important)
    2020-12-01
    oval:org.opensuse.security:def:38785
    P
    python-pywbem on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31425
    P
    Security update for php53 (Important)
    2020-12-01
    oval:com.redhat.rhsa:def:20201112
    P
    RHSA-2020:1112: php security update (Moderate)
    2020-03-31
    oval:com.ubuntu.artful:def:201810547000
    V
    CVE-2018-10547 on Ubuntu 17.10 (artful) - medium.
    2018-04-29
    oval:com.ubuntu.bionic:def:201810547000
    V
    CVE-2018-10547 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-04-29
    oval:com.ubuntu.bionic:def:2018105470000000
    V
    CVE-2018-10547 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-04-29
    oval:com.ubuntu.trusty:def:201810547000
    V
    CVE-2018-10547 on Ubuntu 14.04 LTS (trusty) - medium.
    2018-04-29
    oval:com.ubuntu.xenial:def:2018105470000000
    V
    CVE-2018-10547 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-04-29
    oval:com.ubuntu.xenial:def:201810547000
    V
    CVE-2018-10547 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-04-29
    BACK
    php php *
    php php *
    php php *
    php php *
    canonical ubuntu linux 12.04
    canonical ubuntu linux 14.04
    canonical ubuntu linux 16.04
    canonical ubuntu linux 17.10
    canonical ubuntu linux 18.04
    debian debian linux 7.0
    debian debian linux 8.0
    debian debian linux 9.0
    netapp storage automation store -
    php php 5
    php php 7.0
    ibm lotus protector 2.8.1
    ibm lotus protector 2.8.3
    ibm api connect 5.0.8.3