<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for php5</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2016:1922-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-07-31T23:08:57Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-07-31T23:08:57Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-07-31T23:08:57Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for php5</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for php5 fixes the following issues:

* It is possible to launch a web server with 'php -S localhost:8080'
  It used to be possible to set an arbitrary $HTTP_PROXY environment variable
  for request handlers -- like CGI scripts -- by including a specially crafted
  HTTP header in the request (CVE-2016-5385). As a result, these server
  components would potentially direct all their outgoing HTTP traffic through a
  malicious proxy server. This patch fixes the issue: the updated php server
  ignores such HTTP headers and never sets $HTTP_PROXY for sub-processes.
  (bnc#988486)
* There was multiple cases where a remote attacker could trigger a double free
  and, given specific PHP code using callbacks, trigger code execution vectors.
  (bnc#986246,bnc#986244,CVE-2016-5768,CVE-2016-5772)
* It was possible to inject header or content information (XSS) when a user was 
  using internet explorer as the browser. (bnc#986004, CVE-2015-8935)
* In several cases it was possible for a integer overflow to trigger an 
  excessive memory allocation (bnc#986392, bnc#986388, bnc#986386, bnc#986393, 
  CVE-2016-5770, CVE-2016-5769, CVE-2016-5766, CVE-2016-5767)
* It was possible for an attacker to abuse the garbage collector to free a 
  target array. At this point an attacker could craft a fake zval object and 
  exploit the PHP process by taking over the EIP/RIP. (bnc#986391,
  CVE-2016-5771)

This update was imported from the SUSE:SLE-12:Update update project.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html</URL>
      <Description>E-Mail link for openSUSE-SU-2016:1922-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 42.1">
      <Branch Type="Product Name" Name="openSUSE Leap 42.1">
        <FullProductName ProductID="openSUSE Leap 42.1">openSUSE Leap 42.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="apache2-mod_php5-5.5.14-56.1">
      <FullProductName ProductID="apache2-mod_php5-5.5.14-56.1">apache2-mod_php5-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-5.5.14-56.1">
      <FullProductName ProductID="php5-5.5.14-56.1">php5-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-bcmath-5.5.14-56.1">
      <FullProductName ProductID="php5-bcmath-5.5.14-56.1">php5-bcmath-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-bz2-5.5.14-56.1">
      <FullProductName ProductID="php5-bz2-5.5.14-56.1">php5-bz2-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-calendar-5.5.14-56.1">
      <FullProductName ProductID="php5-calendar-5.5.14-56.1">php5-calendar-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ctype-5.5.14-56.1">
      <FullProductName ProductID="php5-ctype-5.5.14-56.1">php5-ctype-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-curl-5.5.14-56.1">
      <FullProductName ProductID="php5-curl-5.5.14-56.1">php5-curl-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-dba-5.5.14-56.1">
      <FullProductName ProductID="php5-dba-5.5.14-56.1">php5-dba-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-devel-5.5.14-56.1">
      <FullProductName ProductID="php5-devel-5.5.14-56.1">php5-devel-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-dom-5.5.14-56.1">
      <FullProductName ProductID="php5-dom-5.5.14-56.1">php5-dom-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-enchant-5.5.14-56.1">
      <FullProductName ProductID="php5-enchant-5.5.14-56.1">php5-enchant-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-exif-5.5.14-56.1">
      <FullProductName ProductID="php5-exif-5.5.14-56.1">php5-exif-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fastcgi-5.5.14-56.1">
      <FullProductName ProductID="php5-fastcgi-5.5.14-56.1">php5-fastcgi-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fileinfo-5.5.14-56.1">
      <FullProductName ProductID="php5-fileinfo-5.5.14-56.1">php5-fileinfo-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-firebird-5.5.14-56.1">
      <FullProductName ProductID="php5-firebird-5.5.14-56.1">php5-firebird-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fpm-5.5.14-56.1">
      <FullProductName ProductID="php5-fpm-5.5.14-56.1">php5-fpm-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ftp-5.5.14-56.1">
      <FullProductName ProductID="php5-ftp-5.5.14-56.1">php5-ftp-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gd-5.5.14-56.1">
      <FullProductName ProductID="php5-gd-5.5.14-56.1">php5-gd-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gettext-5.5.14-56.1">
      <FullProductName ProductID="php5-gettext-5.5.14-56.1">php5-gettext-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gmp-5.5.14-56.1">
      <FullProductName ProductID="php5-gmp-5.5.14-56.1">php5-gmp-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-iconv-5.5.14-56.1">
      <FullProductName ProductID="php5-iconv-5.5.14-56.1">php5-iconv-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-imap-5.5.14-56.1">
      <FullProductName ProductID="php5-imap-5.5.14-56.1">php5-imap-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-intl-5.5.14-56.1">
      <FullProductName ProductID="php5-intl-5.5.14-56.1">php5-intl-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-json-5.5.14-56.1">
      <FullProductName ProductID="php5-json-5.5.14-56.1">php5-json-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ldap-5.5.14-56.1">
      <FullProductName ProductID="php5-ldap-5.5.14-56.1">php5-ldap-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mbstring-5.5.14-56.1">
      <FullProductName ProductID="php5-mbstring-5.5.14-56.1">php5-mbstring-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mcrypt-5.5.14-56.1">
      <FullProductName ProductID="php5-mcrypt-5.5.14-56.1">php5-mcrypt-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mssql-5.5.14-56.1">
      <FullProductName ProductID="php5-mssql-5.5.14-56.1">php5-mssql-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mysql-5.5.14-56.1">
      <FullProductName ProductID="php5-mysql-5.5.14-56.1">php5-mysql-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-odbc-5.5.14-56.1">
      <FullProductName ProductID="php5-odbc-5.5.14-56.1">php5-odbc-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-opcache-5.5.14-56.1">
      <FullProductName ProductID="php5-opcache-5.5.14-56.1">php5-opcache-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-openssl-5.5.14-56.1">
      <FullProductName ProductID="php5-openssl-5.5.14-56.1">php5-openssl-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pcntl-5.5.14-56.1">
      <FullProductName ProductID="php5-pcntl-5.5.14-56.1">php5-pcntl-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pdo-5.5.14-56.1">
      <FullProductName ProductID="php5-pdo-5.5.14-56.1">php5-pdo-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pear-5.5.14-56.1">
      <FullProductName ProductID="php5-pear-5.5.14-56.1">php5-pear-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pgsql-5.5.14-56.1">
      <FullProductName ProductID="php5-pgsql-5.5.14-56.1">php5-pgsql-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-phar-5.5.14-56.1">
      <FullProductName ProductID="php5-phar-5.5.14-56.1">php5-phar-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-posix-5.5.14-56.1">
      <FullProductName ProductID="php5-posix-5.5.14-56.1">php5-posix-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pspell-5.5.14-56.1">
      <FullProductName ProductID="php5-pspell-5.5.14-56.1">php5-pspell-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-readline-5.5.14-56.1">
      <FullProductName ProductID="php5-readline-5.5.14-56.1">php5-readline-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-shmop-5.5.14-56.1">
      <FullProductName ProductID="php5-shmop-5.5.14-56.1">php5-shmop-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-snmp-5.5.14-56.1">
      <FullProductName ProductID="php5-snmp-5.5.14-56.1">php5-snmp-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-soap-5.5.14-56.1">
      <FullProductName ProductID="php5-soap-5.5.14-56.1">php5-soap-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sockets-5.5.14-56.1">
      <FullProductName ProductID="php5-sockets-5.5.14-56.1">php5-sockets-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sqlite-5.5.14-56.1">
      <FullProductName ProductID="php5-sqlite-5.5.14-56.1">php5-sqlite-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-suhosin-5.5.14-56.1">
      <FullProductName ProductID="php5-suhosin-5.5.14-56.1">php5-suhosin-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvmsg-5.5.14-56.1">
      <FullProductName ProductID="php5-sysvmsg-5.5.14-56.1">php5-sysvmsg-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvsem-5.5.14-56.1">
      <FullProductName ProductID="php5-sysvsem-5.5.14-56.1">php5-sysvsem-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvshm-5.5.14-56.1">
      <FullProductName ProductID="php5-sysvshm-5.5.14-56.1">php5-sysvshm-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-tidy-5.5.14-56.1">
      <FullProductName ProductID="php5-tidy-5.5.14-56.1">php5-tidy-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-tokenizer-5.5.14-56.1">
      <FullProductName ProductID="php5-tokenizer-5.5.14-56.1">php5-tokenizer-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-wddx-5.5.14-56.1">
      <FullProductName ProductID="php5-wddx-5.5.14-56.1">php5-wddx-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlreader-5.5.14-56.1">
      <FullProductName ProductID="php5-xmlreader-5.5.14-56.1">php5-xmlreader-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlrpc-5.5.14-56.1">
      <FullProductName ProductID="php5-xmlrpc-5.5.14-56.1">php5-xmlrpc-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlwriter-5.5.14-56.1">
      <FullProductName ProductID="php5-xmlwriter-5.5.14-56.1">php5-xmlwriter-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xsl-5.5.14-56.1">
      <FullProductName ProductID="php5-xsl-5.5.14-56.1">php5-xsl-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-zip-5.5.14-56.1">
      <FullProductName ProductID="php5-zip-5.5.14-56.1">php5-zip-5.5.14-56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-zlib-5.5.14-56.1">
      <FullProductName ProductID="php5-zlib-5.5.14-56.1">php5-zlib-5.5.14-56.1</FullProductName>
    </Branch>
    <Relationship ProductReference="apache2-mod_php5-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:apache2-mod_php5-5.5.14-56.1">apache2-mod_php5-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-5.5.14-56.1">php5-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-bcmath-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-bcmath-5.5.14-56.1">php5-bcmath-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-bz2-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-bz2-5.5.14-56.1">php5-bz2-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-calendar-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-calendar-5.5.14-56.1">php5-calendar-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ctype-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-ctype-5.5.14-56.1">php5-ctype-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-curl-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-curl-5.5.14-56.1">php5-curl-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-dba-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-dba-5.5.14-56.1">php5-dba-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-devel-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-devel-5.5.14-56.1">php5-devel-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-dom-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-dom-5.5.14-56.1">php5-dom-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-enchant-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-enchant-5.5.14-56.1">php5-enchant-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-exif-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-exif-5.5.14-56.1">php5-exif-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fastcgi-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-fastcgi-5.5.14-56.1">php5-fastcgi-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fileinfo-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-fileinfo-5.5.14-56.1">php5-fileinfo-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-firebird-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-firebird-5.5.14-56.1">php5-firebird-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fpm-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-fpm-5.5.14-56.1">php5-fpm-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ftp-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-ftp-5.5.14-56.1">php5-ftp-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gd-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-gd-5.5.14-56.1">php5-gd-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gettext-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-gettext-5.5.14-56.1">php5-gettext-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gmp-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-gmp-5.5.14-56.1">php5-gmp-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-iconv-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-iconv-5.5.14-56.1">php5-iconv-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-imap-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-imap-5.5.14-56.1">php5-imap-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-intl-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-intl-5.5.14-56.1">php5-intl-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-json-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-json-5.5.14-56.1">php5-json-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ldap-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-ldap-5.5.14-56.1">php5-ldap-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mbstring-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-mbstring-5.5.14-56.1">php5-mbstring-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mcrypt-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-mcrypt-5.5.14-56.1">php5-mcrypt-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mssql-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-mssql-5.5.14-56.1">php5-mssql-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mysql-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-mysql-5.5.14-56.1">php5-mysql-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-odbc-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-odbc-5.5.14-56.1">php5-odbc-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-opcache-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-opcache-5.5.14-56.1">php5-opcache-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-openssl-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-openssl-5.5.14-56.1">php5-openssl-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pcntl-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-pcntl-5.5.14-56.1">php5-pcntl-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pdo-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-pdo-5.5.14-56.1">php5-pdo-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pear-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-pear-5.5.14-56.1">php5-pear-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pgsql-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-pgsql-5.5.14-56.1">php5-pgsql-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-phar-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-phar-5.5.14-56.1">php5-phar-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-posix-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-posix-5.5.14-56.1">php5-posix-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pspell-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-pspell-5.5.14-56.1">php5-pspell-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-readline-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-readline-5.5.14-56.1">php5-readline-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-shmop-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-shmop-5.5.14-56.1">php5-shmop-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-snmp-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-snmp-5.5.14-56.1">php5-snmp-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-soap-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-soap-5.5.14-56.1">php5-soap-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sockets-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-sockets-5.5.14-56.1">php5-sockets-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sqlite-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-sqlite-5.5.14-56.1">php5-sqlite-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-suhosin-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-suhosin-5.5.14-56.1">php5-suhosin-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvmsg-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-sysvmsg-5.5.14-56.1">php5-sysvmsg-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvsem-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-sysvsem-5.5.14-56.1">php5-sysvsem-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvshm-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-sysvshm-5.5.14-56.1">php5-sysvshm-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-tidy-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-tidy-5.5.14-56.1">php5-tidy-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-tokenizer-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-tokenizer-5.5.14-56.1">php5-tokenizer-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-wddx-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-wddx-5.5.14-56.1">php5-wddx-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlreader-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-xmlreader-5.5.14-56.1">php5-xmlreader-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlrpc-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-xmlrpc-5.5.14-56.1">php5-xmlrpc-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlwriter-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-xmlwriter-5.5.14-56.1">php5-xmlwriter-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xsl-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-xsl-5.5.14-56.1">php5-xsl-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-zip-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-zip-5.5.14-56.1">php5-zip-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-zlib-5.5.14-56.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-zlib-5.5.14-56.1">php5-zlib-5.5.14-56.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The sapi_header_op function in main/SAPI.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 supports deprecated line folding without considering browser compatibility, which allows remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer by leveraging (1) %0A%20 or (2) %0D%0A%20 mishandling in the header function.</Note>
    </Notes>
    <CVE>CVE-2015-8935</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-56.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8935.html</URL>
        <Description>CVE-2015-8935</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986004</URL>
        <Description>SUSE Bug 986004</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.</Note>
    </Notes>
    <CVE>CVE-2016-5385</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-56.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5385.html</URL>
        <Description>CVE-2016-5385</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/988484</URL>
        <Description>SUSE Bug 988484</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/988486</URL>
        <Description>SUSE Bug 988486</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/988487</URL>
        <Description>SUSE Bug 988487</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/988488</URL>
        <Description>SUSE Bug 988488</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/988489</URL>
        <Description>SUSE Bug 988489</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/988491</URL>
        <Description>SUSE Bug 988491</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/988492</URL>
        <Description>SUSE Bug 988492</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/989125</URL>
        <Description>SUSE Bug 989125</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/989174</URL>
        <Description>SUSE Bug 989174</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.</Note>
    </Notes>
    <CVE>CVE-2016-5766</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-56.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5766.html</URL>
        <Description>CVE-2016-5766</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986386</URL>
        <Description>SUSE Bug 986386</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the gdImageCreate function in gd.c in the GD Graphics Library (aka libgd) before 2.0.34RC1, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted image dimensions.</Note>
    </Notes>
    <CVE>CVE-2016-5767</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-56.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5767.html</URL>
        <Description>CVE-2016-5767</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986393</URL>
        <Description>SUSE Bug 986393</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by leveraging a callback exception.</Note>
    </Notes>
    <CVE>CVE-2016-5768</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-56.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.4</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5768.html</URL>
        <Description>CVE-2016-5768</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986246</URL>
        <Description>SUSE Bug 986246</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple integer overflows in mcrypt.c in the mcrypt extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted length value, related to the (1) mcrypt_generic and (2) mdecrypt_generic functions.</Note>
    </Notes>
    <CVE>CVE-2016-5769</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-56.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5769.html</URL>
        <Description>CVE-2016-5769</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986388</URL>
        <Description>SUSE Bug 986388</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer argument, a related issue to CVE-2016-5096.</Note>
    </Notes>
    <CVE>CVE-2016-5770</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-56.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.4</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5770.html</URL>
        <Description>CVE-2016-5770</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986392</URL>
        <Description>SUSE Bug 986392</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data.</Note>
    </Notes>
    <CVE>CVE-2016-5771</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-56.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5771.html</URL>
        <Description>CVE-2016-5771</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986247</URL>
        <Description>SUSE Bug 986247</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986391</URL>
        <Description>SUSE Bug 986391</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted XML data that is mishandled in a wddx_deserialize call.</Note>
    </Notes>
    <CVE>CVE-2016-5772</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-56.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-56.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5772.html</URL>
        <Description>CVE-2016-5772</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/986244</URL>
        <Description>SUSE Bug 986244</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
