<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for php5</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2019:1503-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2019-06-03T08:41:42Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2019-06-03T08:41:42Z</InitialReleaseDate>
    <CurrentReleaseDate>2019-06-03T08:41:42Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for php5</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for php5 fixes the following issues:

Security issues fixed:

- CVE-2019-11034: Fixed a heap-buffer overflow in php_ifd_get32si() (bsc#1132838).
- CVE-2019-11035: Fixed a heap-buffer overflow in exif_iif_add_value() (bsc#1132837).
- CVE-2019-9637: Fixed a potential information disclosure in rename() (bsc#1128892).
- CVE-2019-9675: Fixed a potential buffer overflow in phar_tar_writeheaders_int() (bsc#1128886).
- CVE-2019-9638: Fixed an uninitialized read in exif_process_IFD_in_MAKERNOTE() related to value_len (bsc#1128889).
- CVE-2019-9639: Fixed an uninitialized read in exif_process_IFD_in_MAKERNOTE() related to data_len (bsc#1128887).
- CVE-2019-9640: Fixed an invalid Read in exif_process_SOFn() (bsc#1128883).
- CVE-2019-11036: Fixed buffer over-read in exif_process_IFD_TAG function leading to information disclosure (bsc#1134322).

This update was imported from the SUSE:SLE-12:Update update project.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html</URL>
      <Description>E-Mail link for openSUSE-SU-2019:1503-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 42.3">
      <Branch Type="Product Name" Name="openSUSE Leap 42.3">
        <FullProductName ProductID="openSUSE Leap 42.3">openSUSE Leap 42.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="apache2-mod_php5-5.5.14-118.1">
      <FullProductName ProductID="apache2-mod_php5-5.5.14-118.1">apache2-mod_php5-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-5.5.14-118.1">
      <FullProductName ProductID="php5-5.5.14-118.1">php5-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-bcmath-5.5.14-118.1">
      <FullProductName ProductID="php5-bcmath-5.5.14-118.1">php5-bcmath-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-bz2-5.5.14-118.1">
      <FullProductName ProductID="php5-bz2-5.5.14-118.1">php5-bz2-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-calendar-5.5.14-118.1">
      <FullProductName ProductID="php5-calendar-5.5.14-118.1">php5-calendar-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ctype-5.5.14-118.1">
      <FullProductName ProductID="php5-ctype-5.5.14-118.1">php5-ctype-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-curl-5.5.14-118.1">
      <FullProductName ProductID="php5-curl-5.5.14-118.1">php5-curl-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-dba-5.5.14-118.1">
      <FullProductName ProductID="php5-dba-5.5.14-118.1">php5-dba-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-devel-5.5.14-118.1">
      <FullProductName ProductID="php5-devel-5.5.14-118.1">php5-devel-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-dom-5.5.14-118.1">
      <FullProductName ProductID="php5-dom-5.5.14-118.1">php5-dom-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-enchant-5.5.14-118.1">
      <FullProductName ProductID="php5-enchant-5.5.14-118.1">php5-enchant-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-exif-5.5.14-118.1">
      <FullProductName ProductID="php5-exif-5.5.14-118.1">php5-exif-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fastcgi-5.5.14-118.1">
      <FullProductName ProductID="php5-fastcgi-5.5.14-118.1">php5-fastcgi-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fileinfo-5.5.14-118.1">
      <FullProductName ProductID="php5-fileinfo-5.5.14-118.1">php5-fileinfo-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-firebird-5.5.14-118.1">
      <FullProductName ProductID="php5-firebird-5.5.14-118.1">php5-firebird-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fpm-5.5.14-118.1">
      <FullProductName ProductID="php5-fpm-5.5.14-118.1">php5-fpm-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ftp-5.5.14-118.1">
      <FullProductName ProductID="php5-ftp-5.5.14-118.1">php5-ftp-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gd-5.5.14-118.1">
      <FullProductName ProductID="php5-gd-5.5.14-118.1">php5-gd-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gettext-5.5.14-118.1">
      <FullProductName ProductID="php5-gettext-5.5.14-118.1">php5-gettext-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gmp-5.5.14-118.1">
      <FullProductName ProductID="php5-gmp-5.5.14-118.1">php5-gmp-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-iconv-5.5.14-118.1">
      <FullProductName ProductID="php5-iconv-5.5.14-118.1">php5-iconv-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-imap-5.5.14-118.1">
      <FullProductName ProductID="php5-imap-5.5.14-118.1">php5-imap-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-intl-5.5.14-118.1">
      <FullProductName ProductID="php5-intl-5.5.14-118.1">php5-intl-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-json-5.5.14-118.1">
      <FullProductName ProductID="php5-json-5.5.14-118.1">php5-json-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ldap-5.5.14-118.1">
      <FullProductName ProductID="php5-ldap-5.5.14-118.1">php5-ldap-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mbstring-5.5.14-118.1">
      <FullProductName ProductID="php5-mbstring-5.5.14-118.1">php5-mbstring-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mcrypt-5.5.14-118.1">
      <FullProductName ProductID="php5-mcrypt-5.5.14-118.1">php5-mcrypt-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mssql-5.5.14-118.1">
      <FullProductName ProductID="php5-mssql-5.5.14-118.1">php5-mssql-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mysql-5.5.14-118.1">
      <FullProductName ProductID="php5-mysql-5.5.14-118.1">php5-mysql-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-odbc-5.5.14-118.1">
      <FullProductName ProductID="php5-odbc-5.5.14-118.1">php5-odbc-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-opcache-5.5.14-118.1">
      <FullProductName ProductID="php5-opcache-5.5.14-118.1">php5-opcache-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-openssl-5.5.14-118.1">
      <FullProductName ProductID="php5-openssl-5.5.14-118.1">php5-openssl-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pcntl-5.5.14-118.1">
      <FullProductName ProductID="php5-pcntl-5.5.14-118.1">php5-pcntl-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pdo-5.5.14-118.1">
      <FullProductName ProductID="php5-pdo-5.5.14-118.1">php5-pdo-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pear-5.5.14-118.1">
      <FullProductName ProductID="php5-pear-5.5.14-118.1">php5-pear-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pgsql-5.5.14-118.1">
      <FullProductName ProductID="php5-pgsql-5.5.14-118.1">php5-pgsql-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-phar-5.5.14-118.1">
      <FullProductName ProductID="php5-phar-5.5.14-118.1">php5-phar-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-posix-5.5.14-118.1">
      <FullProductName ProductID="php5-posix-5.5.14-118.1">php5-posix-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pspell-5.5.14-118.1">
      <FullProductName ProductID="php5-pspell-5.5.14-118.1">php5-pspell-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-readline-5.5.14-118.1">
      <FullProductName ProductID="php5-readline-5.5.14-118.1">php5-readline-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-shmop-5.5.14-118.1">
      <FullProductName ProductID="php5-shmop-5.5.14-118.1">php5-shmop-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-snmp-5.5.14-118.1">
      <FullProductName ProductID="php5-snmp-5.5.14-118.1">php5-snmp-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-soap-5.5.14-118.1">
      <FullProductName ProductID="php5-soap-5.5.14-118.1">php5-soap-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sockets-5.5.14-118.1">
      <FullProductName ProductID="php5-sockets-5.5.14-118.1">php5-sockets-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sqlite-5.5.14-118.1">
      <FullProductName ProductID="php5-sqlite-5.5.14-118.1">php5-sqlite-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-suhosin-5.5.14-118.1">
      <FullProductName ProductID="php5-suhosin-5.5.14-118.1">php5-suhosin-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvmsg-5.5.14-118.1">
      <FullProductName ProductID="php5-sysvmsg-5.5.14-118.1">php5-sysvmsg-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvsem-5.5.14-118.1">
      <FullProductName ProductID="php5-sysvsem-5.5.14-118.1">php5-sysvsem-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvshm-5.5.14-118.1">
      <FullProductName ProductID="php5-sysvshm-5.5.14-118.1">php5-sysvshm-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-tidy-5.5.14-118.1">
      <FullProductName ProductID="php5-tidy-5.5.14-118.1">php5-tidy-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-tokenizer-5.5.14-118.1">
      <FullProductName ProductID="php5-tokenizer-5.5.14-118.1">php5-tokenizer-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-wddx-5.5.14-118.1">
      <FullProductName ProductID="php5-wddx-5.5.14-118.1">php5-wddx-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlreader-5.5.14-118.1">
      <FullProductName ProductID="php5-xmlreader-5.5.14-118.1">php5-xmlreader-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlrpc-5.5.14-118.1">
      <FullProductName ProductID="php5-xmlrpc-5.5.14-118.1">php5-xmlrpc-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlwriter-5.5.14-118.1">
      <FullProductName ProductID="php5-xmlwriter-5.5.14-118.1">php5-xmlwriter-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xsl-5.5.14-118.1">
      <FullProductName ProductID="php5-xsl-5.5.14-118.1">php5-xsl-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-zip-5.5.14-118.1">
      <FullProductName ProductID="php5-zip-5.5.14-118.1">php5-zip-5.5.14-118.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-zlib-5.5.14-118.1">
      <FullProductName ProductID="php5-zlib-5.5.14-118.1">php5-zlib-5.5.14-118.1</FullProductName>
    </Branch>
    <Relationship ProductReference="apache2-mod_php5-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:apache2-mod_php5-5.5.14-118.1">apache2-mod_php5-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-5.5.14-118.1">php5-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-bcmath-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-bcmath-5.5.14-118.1">php5-bcmath-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-bz2-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-bz2-5.5.14-118.1">php5-bz2-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-calendar-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-calendar-5.5.14-118.1">php5-calendar-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ctype-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-ctype-5.5.14-118.1">php5-ctype-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-curl-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-curl-5.5.14-118.1">php5-curl-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-dba-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-dba-5.5.14-118.1">php5-dba-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-devel-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-devel-5.5.14-118.1">php5-devel-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-dom-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-dom-5.5.14-118.1">php5-dom-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-enchant-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-enchant-5.5.14-118.1">php5-enchant-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-exif-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-exif-5.5.14-118.1">php5-exif-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fastcgi-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-fastcgi-5.5.14-118.1">php5-fastcgi-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fileinfo-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-fileinfo-5.5.14-118.1">php5-fileinfo-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-firebird-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-firebird-5.5.14-118.1">php5-firebird-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fpm-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-fpm-5.5.14-118.1">php5-fpm-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ftp-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-ftp-5.5.14-118.1">php5-ftp-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gd-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-gd-5.5.14-118.1">php5-gd-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gettext-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-gettext-5.5.14-118.1">php5-gettext-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gmp-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-gmp-5.5.14-118.1">php5-gmp-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-iconv-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-iconv-5.5.14-118.1">php5-iconv-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-imap-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-imap-5.5.14-118.1">php5-imap-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-intl-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-intl-5.5.14-118.1">php5-intl-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-json-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-json-5.5.14-118.1">php5-json-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ldap-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-ldap-5.5.14-118.1">php5-ldap-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mbstring-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-mbstring-5.5.14-118.1">php5-mbstring-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mcrypt-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-mcrypt-5.5.14-118.1">php5-mcrypt-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mssql-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-mssql-5.5.14-118.1">php5-mssql-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mysql-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-mysql-5.5.14-118.1">php5-mysql-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-odbc-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-odbc-5.5.14-118.1">php5-odbc-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-opcache-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-opcache-5.5.14-118.1">php5-opcache-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-openssl-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-openssl-5.5.14-118.1">php5-openssl-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pcntl-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-pcntl-5.5.14-118.1">php5-pcntl-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pdo-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-pdo-5.5.14-118.1">php5-pdo-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pear-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-pear-5.5.14-118.1">php5-pear-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pgsql-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-pgsql-5.5.14-118.1">php5-pgsql-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-phar-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-phar-5.5.14-118.1">php5-phar-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-posix-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-posix-5.5.14-118.1">php5-posix-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pspell-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-pspell-5.5.14-118.1">php5-pspell-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-readline-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-readline-5.5.14-118.1">php5-readline-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-shmop-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-shmop-5.5.14-118.1">php5-shmop-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-snmp-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-snmp-5.5.14-118.1">php5-snmp-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-soap-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-soap-5.5.14-118.1">php5-soap-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sockets-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-sockets-5.5.14-118.1">php5-sockets-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sqlite-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-sqlite-5.5.14-118.1">php5-sqlite-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-suhosin-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-suhosin-5.5.14-118.1">php5-suhosin-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvmsg-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-sysvmsg-5.5.14-118.1">php5-sysvmsg-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvsem-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-sysvsem-5.5.14-118.1">php5-sysvsem-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvshm-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-sysvshm-5.5.14-118.1">php5-sysvshm-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-tidy-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-tidy-5.5.14-118.1">php5-tidy-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-tokenizer-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-tokenizer-5.5.14-118.1">php5-tokenizer-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-wddx-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-wddx-5.5.14-118.1">php5-wddx-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlreader-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-xmlreader-5.5.14-118.1">php5-xmlreader-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlrpc-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-xmlrpc-5.5.14-118.1">php5-xmlrpc-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlwriter-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-xmlwriter-5.5.14-118.1">php5-xmlwriter-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xsl-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-xsl-5.5.14-118.1">php5-xsl-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-zip-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-zip-5.5.14-118.1">php5-zip-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-zlib-5.5.14-118.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:php5-zlib-5.5.14-118.1">php5-zlib-5.5.14-118.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11034</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:apache2-mod_php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bcmath-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bz2-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-calendar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ctype-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-curl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dba-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-devel-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dom-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-enchant-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-exif-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fastcgi-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fileinfo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-firebird-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fpm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ftp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gd-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gettext-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-iconv-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-imap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-intl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-json-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ldap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mbstring-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mcrypt-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mssql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mysql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-odbc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-opcache-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-openssl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pcntl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pdo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pear-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pgsql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-phar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-posix-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pspell-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-readline-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-shmop-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-snmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-soap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sockets-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sqlite-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-suhosin-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvmsg-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvsem-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvshm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tidy-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tokenizer-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-wddx-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlreader-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlrpc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlwriter-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xsl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zip-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zlib-5.5.14-118.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11034.html</URL>
        <Description>CVE-2019-11034</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1132838</URL>
        <Description>SUSE Bug 1132838</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11035</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:apache2-mod_php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bcmath-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bz2-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-calendar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ctype-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-curl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dba-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-devel-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dom-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-enchant-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-exif-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fastcgi-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fileinfo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-firebird-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fpm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ftp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gd-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gettext-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-iconv-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-imap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-intl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-json-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ldap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mbstring-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mcrypt-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mssql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mysql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-odbc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-opcache-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-openssl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pcntl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pdo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pear-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pgsql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-phar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-posix-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pspell-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-readline-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-shmop-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-snmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-soap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sockets-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sqlite-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-suhosin-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvmsg-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvsem-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvshm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tidy-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tokenizer-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-wddx-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlreader-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlrpc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlwriter-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xsl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zip-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zlib-5.5.14-118.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11035.html</URL>
        <Description>CVE-2019-11035</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1132837</URL>
        <Description>SUSE Bug 1132837</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11036</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:apache2-mod_php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bcmath-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bz2-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-calendar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ctype-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-curl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dba-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-devel-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dom-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-enchant-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-exif-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fastcgi-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fileinfo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-firebird-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fpm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ftp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gd-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gettext-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-iconv-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-imap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-intl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-json-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ldap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mbstring-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mcrypt-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mssql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mysql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-odbc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-opcache-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-openssl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pcntl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pdo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pear-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pgsql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-phar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-posix-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pspell-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-readline-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-shmop-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-snmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-soap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sockets-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sqlite-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-suhosin-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvmsg-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvsem-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvshm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tidy-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tokenizer-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-wddx-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlreader-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlrpc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlwriter-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xsl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zip-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zlib-5.5.14-118.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11036.html</URL>
        <Description>CVE-2019-11036</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1134322</URL>
        <Description>SUSE Bug 1134322</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.</Note>
    </Notes>
    <CVE>CVE-2019-9637</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:apache2-mod_php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bcmath-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bz2-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-calendar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ctype-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-curl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dba-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-devel-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dom-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-enchant-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-exif-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fastcgi-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fileinfo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-firebird-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fpm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ftp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gd-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gettext-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-iconv-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-imap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-intl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-json-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ldap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mbstring-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mcrypt-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mssql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mysql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-odbc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-opcache-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-openssl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pcntl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pdo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pear-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pgsql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-phar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-posix-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pspell-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-readline-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-shmop-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-snmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-soap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sockets-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sqlite-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-suhosin-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvmsg-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvsem-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvshm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tidy-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tokenizer-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-wddx-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlreader-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlrpc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlwriter-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xsl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zip-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zlib-5.5.14-118.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9637.html</URL>
        <Description>CVE-2019-9637</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128892</URL>
        <Description>SUSE Bug 1128892</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the maker_note-&gt;offset relationship to value_len.</Note>
    </Notes>
    <CVE>CVE-2019-9638</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:apache2-mod_php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bcmath-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bz2-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-calendar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ctype-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-curl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dba-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-devel-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dom-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-enchant-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-exif-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fastcgi-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fileinfo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-firebird-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fpm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ftp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gd-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gettext-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-iconv-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-imap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-intl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-json-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ldap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mbstring-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mcrypt-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mssql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mysql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-odbc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-opcache-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-openssl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pcntl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pdo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pear-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pgsql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-phar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-posix-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pspell-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-readline-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-shmop-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-snmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-soap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sockets-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sqlite-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-suhosin-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvmsg-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvsem-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvshm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tidy-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tokenizer-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-wddx-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlreader-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlrpc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlwriter-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xsl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zip-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zlib-5.5.14-118.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9638.html</URL>
        <Description>CVE-2019-9638</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128889</URL>
        <Description>SUSE Bug 1128889</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.</Note>
    </Notes>
    <CVE>CVE-2019-9639</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:apache2-mod_php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bcmath-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bz2-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-calendar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ctype-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-curl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dba-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-devel-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dom-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-enchant-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-exif-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fastcgi-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fileinfo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-firebird-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fpm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ftp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gd-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gettext-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-iconv-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-imap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-intl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-json-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ldap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mbstring-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mcrypt-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mssql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mysql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-odbc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-opcache-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-openssl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pcntl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pdo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pear-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pgsql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-phar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-posix-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pspell-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-readline-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-shmop-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-snmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-soap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sockets-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sqlite-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-suhosin-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvmsg-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvsem-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvshm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tidy-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tokenizer-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-wddx-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlreader-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlrpc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlwriter-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xsl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zip-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zlib-5.5.14-118.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9639.html</URL>
        <Description>CVE-2019-9639</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128887</URL>
        <Description>SUSE Bug 1128887</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_process_SOFn.</Note>
    </Notes>
    <CVE>CVE-2019-9640</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:apache2-mod_php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bcmath-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bz2-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-calendar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ctype-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-curl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dba-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-devel-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dom-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-enchant-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-exif-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fastcgi-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fileinfo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-firebird-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fpm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ftp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gd-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gettext-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-iconv-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-imap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-intl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-json-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ldap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mbstring-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mcrypt-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mssql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mysql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-odbc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-opcache-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-openssl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pcntl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pdo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pear-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pgsql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-phar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-posix-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pspell-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-readline-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-shmop-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-snmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-soap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sockets-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sqlite-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-suhosin-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvmsg-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvsem-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvshm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tidy-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tokenizer-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-wddx-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlreader-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlrpc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlwriter-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xsl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zip-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zlib-5.5.14-118.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9640.html</URL>
        <Description>CVE-2019-9640</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128883</URL>
        <Description>SUSE Bug 1128883</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** DISPUTED ** An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a symlink, which currently cannot happen: "This issue allows theoretical compromise of security, but a practical attack is usually impossible."</Note>
    </Notes>
    <CVE>CVE-2019-9675</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:apache2-mod_php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bcmath-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-bz2-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-calendar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ctype-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-curl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dba-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-devel-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-dom-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-enchant-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-exif-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fastcgi-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fileinfo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-firebird-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-fpm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ftp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gd-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gettext-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-gmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-iconv-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-imap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-intl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-json-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-ldap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mbstring-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mcrypt-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mssql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-mysql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-odbc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-opcache-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-openssl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pcntl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pdo-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pear-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pgsql-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-phar-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-posix-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-pspell-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-readline-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-shmop-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-snmp-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-soap-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sockets-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sqlite-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-suhosin-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvmsg-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvsem-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-sysvshm-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tidy-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-tokenizer-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-wddx-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlreader-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlrpc-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xmlwriter-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-xsl-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zip-5.5.14-118.1</ProductID>
        <ProductID>openSUSE Leap 42.3:php5-zlib-5.5.14-118.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9675.html</URL>
        <Description>CVE-2019-9675</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128886</URL>
        <Description>SUSE Bug 1128886</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
