php: security bump to version 5.5.16
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Fri, 22 Aug 2014 13:49:03 +0000 (10:49 -0300)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Mon, 25 Aug 2014 17:50:30 +0000 (19:50 +0200)
Fixes:
CVE-2014-3538 - Extensive backtracking in rule regular expression
CVE-2014-3587 - Segfault in cdf.c
CVE-2014-2497 - php-gd 'c_color' NULL pointer dereference
CVE-2014-5120 - Null byte injection possible with imagexxx functions
CVE-2014-3597 - segfault in dns_get_record

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/php/php.mk

index de7d668355d11e58d1742f6a4dd39e6ba7b7cd21..d174533f01561b525878c9c9dd184b1d8246ec08 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-PHP_VERSION = 5.5.15
+PHP_VERSION = 5.5.16
 PHP_SITE = http://www.php.net/distributions
 PHP_INSTALL_STAGING = YES
 PHP_INSTALL_STAGING_OPT = INSTALL_ROOT=$(STAGING_DIR) install