{"affected":[{"ecosystem_specific":{"binaries":[{"apache2-mod_php5":"5.2.14-0.7.30.72.1","php5":"5.2.14-0.7.30.72.1","php5-bcmath":"5.2.14-0.7.30.72.1","php5-bz2":"5.2.14-0.7.30.72.1","php5-calendar":"5.2.14-0.7.30.72.1","php5-ctype":"5.2.14-0.7.30.72.1","php5-curl":"5.2.14-0.7.30.72.1","php5-dba":"5.2.14-0.7.30.72.1","php5-dbase":"5.2.14-0.7.30.72.1","php5-dom":"5.2.14-0.7.30.72.1","php5-exif":"5.2.14-0.7.30.72.1","php5-fastcgi":"5.2.14-0.7.30.72.1","php5-ftp":"5.2.14-0.7.30.72.1","php5-gd":"5.2.14-0.7.30.72.1","php5-gettext":"5.2.14-0.7.30.72.1","php5-gmp":"5.2.14-0.7.30.72.1","php5-hash":"5.2.14-0.7.30.72.1","php5-iconv":"5.2.14-0.7.30.72.1","php5-json":"5.2.14-0.7.30.72.1","php5-ldap":"5.2.14-0.7.30.72.1","php5-mbstring":"5.2.14-0.7.30.72.1","php5-mcrypt":"5.2.14-0.7.30.72.1","php5-mysql":"5.2.14-0.7.30.72.1","php5-odbc":"5.2.14-0.7.30.72.1","php5-openssl":"5.2.14-0.7.30.72.1","php5-pcntl":"5.2.14-0.7.30.72.1","php5-pdo":"5.2.14-0.7.30.72.1","php5-pear":"5.2.14-0.7.30.72.1","php5-pgsql":"5.2.14-0.7.30.72.1","php5-pspell":"5.2.14-0.7.30.72.1","php5-shmop":"5.2.14-0.7.30.72.1","php5-snmp":"5.2.14-0.7.30.72.1","php5-soap":"5.2.14-0.7.30.72.1","php5-suhosin":"5.2.14-0.7.30.72.1","php5-sysvmsg":"5.2.14-0.7.30.72.1","php5-sysvsem":"5.2.14-0.7.30.72.1","php5-sysvshm":"5.2.14-0.7.30.72.1","php5-tokenizer":"5.2.14-0.7.30.72.1","php5-wddx":"5.2.14-0.7.30.72.1","php5-xmlreader":"5.2.14-0.7.30.72.1","php5-xmlrpc":"5.2.14-0.7.30.72.1","php5-xmlwriter":"5.2.14-0.7.30.72.1","php5-xsl":"5.2.14-0.7.30.72.1","php5-zip":"5.2.14-0.7.30.72.1","php5-zlib":"5.2.14-0.7.30.72.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP2-LTSS","name":"php5","purl":"pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"5.2.14-0.7.30.72.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThe PHP5 script interpreter was updated to fix security issues:\n\n* CVE-2015-6836: A SOAP serialize_function_call() type confusion leading to remote code execution problem was fixed. [bnc#945428]\n* CVE-2015-6837 CVE-2015-6838: Two NULL pointer dereferences in the XSLTProcessor class were fixed. [bnc#945412]\n","id":"SUSE-SU-2015:1701-1","modified":"2015-09-17T12:16:39Z","published":"2015-09-17T12:16:39Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20151701-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/945412"},{"type":"REPORT","url":"https://bugzilla.suse.com/945428"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-6836"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-6837"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-6838"}],"related":["CVE-2015-6836","CVE-2015-6837","CVE-2015-6838"],"summary":"Security update for php5","upstream":["CVE-2015-6836","CVE-2015-6837","CVE-2015-6838"]}