<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for php5</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2016:2451-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-10-04T11:46:06Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-10-04T11:46:06Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-10-04T11:46:06Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for php5</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This update for php5 fixes the following security issues:

* CVE-2016-6128: Invalid color index not properly handled [bsc#987580]
* CVE-2016-6161: global out of bounds read when encoding gif from malformed input withgd2togif [bsc#988032]
* CVE-2016-6292: Null pointer dereference in exif_process_user_comment [bsc#991422]
* CVE-2016-6295: Use after free in SNMP with GC and unserialize() [bsc#991424]
* CVE-2016-6297: Stack-based buffer overflow vulnerability in php_stream_zip_opener [bsc#991426]
* CVE-2016-6291: Out-of-bounds access in exif_process_IFD_in_MAKERNOTE [bsc#991427]
* CVE-2016-6289: Integer overflow leads to buffer overflow in virtual_file_ex [bsc#991428]
* CVE-2016-6290: Use after free in unserialize() with Unexpected Session Deserialization [bsc#991429]
* CVE-2016-5399: Improper error handling in bzread() [bsc#991430]
* CVE-2016-6296: Heap buffer overflow vulnerability in simplestring_addn in simplestring.c [bsc#991437]
* CVE-2016-6207: Integer overflow error within _gdContributionsAlloc() [bsc#991434]
* CVE-2014-3587: Integer overflow in the cdf_read_property_info affecting SLES11 SP3 [bsc#987530]
* CVE-2016-6288: Buffer over-read in php_url_parse_ex [bsc#991433]
* CVE-2016-7124: Create an Unexpected Object and Don't Invoke __wakeup() in Deserialization
* CVE-2016-7125: PHP Session Data Injection Vulnerability
* CVE-2016-7126: select_colors write out-of-bounds
* CVE-2016-7127: imagegammacorrect allowed arbitrary write access
* CVE-2016-7128: Memory Leakage In exif_process_IFD_in_TIFF
* CVE-2016-7129: wddx_deserialize allowed illegal memory access
* CVE-2016-7130: wddx_deserialize null dereference
* CVE-2016-7131: wddx_deserialize null dereference with invalid xml
* CVE-2016-7132: wddx_deserialize null dereference in php_wddx_pop_element
* CVE-2016-7134: Heap overflow in the function curl_escape

This update was imported from the SUSE:SLE-12:Update update project.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      <Description>E-Mail link for openSUSE-SU-2016:2451-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 42.1">
      <Branch Type="Product Name" Name="openSUSE Leap 42.1">
        <FullProductName ProductID="openSUSE Leap 42.1">openSUSE Leap 42.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="apache2-mod_php5-5.5.14-59.1">
      <FullProductName ProductID="apache2-mod_php5-5.5.14-59.1">apache2-mod_php5-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-5.5.14-59.1">
      <FullProductName ProductID="php5-5.5.14-59.1">php5-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-bcmath-5.5.14-59.1">
      <FullProductName ProductID="php5-bcmath-5.5.14-59.1">php5-bcmath-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-bz2-5.5.14-59.1">
      <FullProductName ProductID="php5-bz2-5.5.14-59.1">php5-bz2-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-calendar-5.5.14-59.1">
      <FullProductName ProductID="php5-calendar-5.5.14-59.1">php5-calendar-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ctype-5.5.14-59.1">
      <FullProductName ProductID="php5-ctype-5.5.14-59.1">php5-ctype-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-curl-5.5.14-59.1">
      <FullProductName ProductID="php5-curl-5.5.14-59.1">php5-curl-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-dba-5.5.14-59.1">
      <FullProductName ProductID="php5-dba-5.5.14-59.1">php5-dba-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-devel-5.5.14-59.1">
      <FullProductName ProductID="php5-devel-5.5.14-59.1">php5-devel-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-dom-5.5.14-59.1">
      <FullProductName ProductID="php5-dom-5.5.14-59.1">php5-dom-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-enchant-5.5.14-59.1">
      <FullProductName ProductID="php5-enchant-5.5.14-59.1">php5-enchant-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-exif-5.5.14-59.1">
      <FullProductName ProductID="php5-exif-5.5.14-59.1">php5-exif-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fastcgi-5.5.14-59.1">
      <FullProductName ProductID="php5-fastcgi-5.5.14-59.1">php5-fastcgi-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fileinfo-5.5.14-59.1">
      <FullProductName ProductID="php5-fileinfo-5.5.14-59.1">php5-fileinfo-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-firebird-5.5.14-59.1">
      <FullProductName ProductID="php5-firebird-5.5.14-59.1">php5-firebird-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fpm-5.5.14-59.1">
      <FullProductName ProductID="php5-fpm-5.5.14-59.1">php5-fpm-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ftp-5.5.14-59.1">
      <FullProductName ProductID="php5-ftp-5.5.14-59.1">php5-ftp-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gd-5.5.14-59.1">
      <FullProductName ProductID="php5-gd-5.5.14-59.1">php5-gd-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gettext-5.5.14-59.1">
      <FullProductName ProductID="php5-gettext-5.5.14-59.1">php5-gettext-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gmp-5.5.14-59.1">
      <FullProductName ProductID="php5-gmp-5.5.14-59.1">php5-gmp-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-iconv-5.5.14-59.1">
      <FullProductName ProductID="php5-iconv-5.5.14-59.1">php5-iconv-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-imap-5.5.14-59.1">
      <FullProductName ProductID="php5-imap-5.5.14-59.1">php5-imap-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-intl-5.5.14-59.1">
      <FullProductName ProductID="php5-intl-5.5.14-59.1">php5-intl-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-json-5.5.14-59.1">
      <FullProductName ProductID="php5-json-5.5.14-59.1">php5-json-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ldap-5.5.14-59.1">
      <FullProductName ProductID="php5-ldap-5.5.14-59.1">php5-ldap-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mbstring-5.5.14-59.1">
      <FullProductName ProductID="php5-mbstring-5.5.14-59.1">php5-mbstring-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mcrypt-5.5.14-59.1">
      <FullProductName ProductID="php5-mcrypt-5.5.14-59.1">php5-mcrypt-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mssql-5.5.14-59.1">
      <FullProductName ProductID="php5-mssql-5.5.14-59.1">php5-mssql-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mysql-5.5.14-59.1">
      <FullProductName ProductID="php5-mysql-5.5.14-59.1">php5-mysql-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-odbc-5.5.14-59.1">
      <FullProductName ProductID="php5-odbc-5.5.14-59.1">php5-odbc-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-opcache-5.5.14-59.1">
      <FullProductName ProductID="php5-opcache-5.5.14-59.1">php5-opcache-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-openssl-5.5.14-59.1">
      <FullProductName ProductID="php5-openssl-5.5.14-59.1">php5-openssl-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pcntl-5.5.14-59.1">
      <FullProductName ProductID="php5-pcntl-5.5.14-59.1">php5-pcntl-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pdo-5.5.14-59.1">
      <FullProductName ProductID="php5-pdo-5.5.14-59.1">php5-pdo-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pear-5.5.14-59.1">
      <FullProductName ProductID="php5-pear-5.5.14-59.1">php5-pear-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pgsql-5.5.14-59.1">
      <FullProductName ProductID="php5-pgsql-5.5.14-59.1">php5-pgsql-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-phar-5.5.14-59.1">
      <FullProductName ProductID="php5-phar-5.5.14-59.1">php5-phar-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-posix-5.5.14-59.1">
      <FullProductName ProductID="php5-posix-5.5.14-59.1">php5-posix-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pspell-5.5.14-59.1">
      <FullProductName ProductID="php5-pspell-5.5.14-59.1">php5-pspell-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-readline-5.5.14-59.1">
      <FullProductName ProductID="php5-readline-5.5.14-59.1">php5-readline-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-shmop-5.5.14-59.1">
      <FullProductName ProductID="php5-shmop-5.5.14-59.1">php5-shmop-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-snmp-5.5.14-59.1">
      <FullProductName ProductID="php5-snmp-5.5.14-59.1">php5-snmp-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-soap-5.5.14-59.1">
      <FullProductName ProductID="php5-soap-5.5.14-59.1">php5-soap-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sockets-5.5.14-59.1">
      <FullProductName ProductID="php5-sockets-5.5.14-59.1">php5-sockets-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sqlite-5.5.14-59.1">
      <FullProductName ProductID="php5-sqlite-5.5.14-59.1">php5-sqlite-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-suhosin-5.5.14-59.1">
      <FullProductName ProductID="php5-suhosin-5.5.14-59.1">php5-suhosin-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvmsg-5.5.14-59.1">
      <FullProductName ProductID="php5-sysvmsg-5.5.14-59.1">php5-sysvmsg-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvsem-5.5.14-59.1">
      <FullProductName ProductID="php5-sysvsem-5.5.14-59.1">php5-sysvsem-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvshm-5.5.14-59.1">
      <FullProductName ProductID="php5-sysvshm-5.5.14-59.1">php5-sysvshm-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-tidy-5.5.14-59.1">
      <FullProductName ProductID="php5-tidy-5.5.14-59.1">php5-tidy-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-tokenizer-5.5.14-59.1">
      <FullProductName ProductID="php5-tokenizer-5.5.14-59.1">php5-tokenizer-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-wddx-5.5.14-59.1">
      <FullProductName ProductID="php5-wddx-5.5.14-59.1">php5-wddx-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlreader-5.5.14-59.1">
      <FullProductName ProductID="php5-xmlreader-5.5.14-59.1">php5-xmlreader-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlrpc-5.5.14-59.1">
      <FullProductName ProductID="php5-xmlrpc-5.5.14-59.1">php5-xmlrpc-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlwriter-5.5.14-59.1">
      <FullProductName ProductID="php5-xmlwriter-5.5.14-59.1">php5-xmlwriter-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xsl-5.5.14-59.1">
      <FullProductName ProductID="php5-xsl-5.5.14-59.1">php5-xsl-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-zip-5.5.14-59.1">
      <FullProductName ProductID="php5-zip-5.5.14-59.1">php5-zip-5.5.14-59.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-zlib-5.5.14-59.1">
      <FullProductName ProductID="php5-zlib-5.5.14-59.1">php5-zlib-5.5.14-59.1</FullProductName>
    </Branch>
    <Relationship ProductReference="apache2-mod_php5-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1">apache2-mod_php5-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-5.5.14-59.1">php5-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-bcmath-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1">php5-bcmath-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-bz2-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-bz2-5.5.14-59.1">php5-bz2-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-calendar-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-calendar-5.5.14-59.1">php5-calendar-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ctype-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-ctype-5.5.14-59.1">php5-ctype-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-curl-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-curl-5.5.14-59.1">php5-curl-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-dba-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-dba-5.5.14-59.1">php5-dba-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-devel-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-devel-5.5.14-59.1">php5-devel-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-dom-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-dom-5.5.14-59.1">php5-dom-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-enchant-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-enchant-5.5.14-59.1">php5-enchant-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-exif-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-exif-5.5.14-59.1">php5-exif-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fastcgi-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1">php5-fastcgi-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fileinfo-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1">php5-fileinfo-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-firebird-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-firebird-5.5.14-59.1">php5-firebird-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fpm-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-fpm-5.5.14-59.1">php5-fpm-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ftp-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-ftp-5.5.14-59.1">php5-ftp-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gd-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-gd-5.5.14-59.1">php5-gd-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gettext-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-gettext-5.5.14-59.1">php5-gettext-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gmp-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-gmp-5.5.14-59.1">php5-gmp-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-iconv-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-iconv-5.5.14-59.1">php5-iconv-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-imap-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-imap-5.5.14-59.1">php5-imap-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-intl-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-intl-5.5.14-59.1">php5-intl-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-json-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-json-5.5.14-59.1">php5-json-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ldap-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-ldap-5.5.14-59.1">php5-ldap-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mbstring-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1">php5-mbstring-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mcrypt-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1">php5-mcrypt-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mssql-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-mssql-5.5.14-59.1">php5-mssql-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mysql-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-mysql-5.5.14-59.1">php5-mysql-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-odbc-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-odbc-5.5.14-59.1">php5-odbc-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-opcache-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-opcache-5.5.14-59.1">php5-opcache-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-openssl-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-openssl-5.5.14-59.1">php5-openssl-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pcntl-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1">php5-pcntl-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pdo-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-pdo-5.5.14-59.1">php5-pdo-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pear-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-pear-5.5.14-59.1">php5-pear-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pgsql-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1">php5-pgsql-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-phar-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-phar-5.5.14-59.1">php5-phar-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-posix-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-posix-5.5.14-59.1">php5-posix-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pspell-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-pspell-5.5.14-59.1">php5-pspell-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-readline-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-readline-5.5.14-59.1">php5-readline-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-shmop-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-shmop-5.5.14-59.1">php5-shmop-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-snmp-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-snmp-5.5.14-59.1">php5-snmp-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-soap-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-soap-5.5.14-59.1">php5-soap-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sockets-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-sockets-5.5.14-59.1">php5-sockets-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sqlite-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1">php5-sqlite-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-suhosin-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1">php5-suhosin-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvmsg-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1">php5-sysvmsg-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvsem-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1">php5-sysvsem-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvshm-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1">php5-sysvshm-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-tidy-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-tidy-5.5.14-59.1">php5-tidy-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-tokenizer-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1">php5-tokenizer-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-wddx-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-wddx-5.5.14-59.1">php5-wddx-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlreader-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1">php5-xmlreader-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlrpc-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1">php5-xmlrpc-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlwriter-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1">php5-xmlwriter-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xsl-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-xsl-5.5.14-59.1">php5-xsl-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-zip-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-zip-5.5.14-59.1">php5-zip-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-zlib-5.5.14-59.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.1">
      <FullProductName ProductID="openSUSE Leap 42.1:php5-zlib-5.5.14-59.1">php5-zlib-5.5.14-59.1 as a component of openSUSE Leap 42.1</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.</Note>
    </Notes>
    <CVE>CVE-2014-3587</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3587.html</URL>
        <Description>CVE-2014-3587</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/987530</URL>
        <Description>SUSE Bug 987530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/998845</URL>
        <Description>SUSE Bug 998845</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot.</Note>
    </Notes>
    <CVE>CVE-2016-3587</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-3587.html</URL>
        <Description>CVE-2016-3587</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/989721</URL>
        <Description>SUSE Bug 989721</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/998845</URL>
        <Description>SUSE Bug 998845</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.</Note>
    </Notes>
    <CVE>CVE-2016-5399</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5399.html</URL>
        <Description>CVE-2016-5399</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991430</URL>
        <Description>SUSE Bug 991430</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.</Note>
    </Notes>
    <CVE>CVE-2016-6128</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-6128.html</URL>
        <Description>CVE-2016-6128</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/987580</URL>
        <Description>SUSE Bug 987580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991710</URL>
        <Description>SUSE Bug 991710</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.</Note>
    </Notes>
    <CVE>CVE-2016-6161</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-6161.html</URL>
        <Description>CVE-2016-6161</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/988032</URL>
        <Description>SUSE Bug 988032</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.</Note>
    </Notes>
    <CVE>CVE-2016-6207</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-6207.html</URL>
        <Description>CVE-2016-6207</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991434</URL>
        <Description>SUSE Bug 991434</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991622</URL>
        <Description>SUSE Bug 991622</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.</Note>
    </Notes>
    <CVE>CVE-2016-6288</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-6288.html</URL>
        <Description>CVE-2016-6288</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991433</URL>
        <Description>SUSE Bug 991433</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.</Note>
    </Notes>
    <CVE>CVE-2016-6289</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-6289.html</URL>
        <Description>CVE-2016-6289</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991428</URL>
        <Description>SUSE Bug 991428</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to session deserialization.</Note>
    </Notes>
    <CVE>CVE-2016-6290</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-6290.html</URL>
        <Description>CVE-2016-6290</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991429</URL>
        <Description>SUSE Bug 991429</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.</Note>
    </Notes>
    <CVE>CVE-2016-6291</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-6291.html</URL>
        <Description>CVE-2016-6291</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991427</URL>
        <Description>SUSE Bug 991427</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The exif_process_user_comment function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted JPEG image.</Note>
    </Notes>
    <CVE>CVE-2016-6292</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-6292.html</URL>
        <Description>CVE-2016-6292</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991422</URL>
        <Description>SUSE Bug 991422</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/snmp/snmp.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via crafted serialized data, a related issue to CVE-2016-5773.</Note>
    </Notes>
    <CVE>CVE-2016-6295</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-6295.html</URL>
        <Description>CVE-2016-6295</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991424</URL>
        <Description>SUSE Bug 991424</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer signedness error in the simplestring_addn function in simplestring.c in xmlrpc-epi through 0.54.2, as used in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a long first argument to the PHP xmlrpc_encode_request function.</Note>
    </Notes>
    <CVE>CVE-2016-6296</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.7</BaseScore>
        <Vector>AV:L/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-6296.html</URL>
        <Description>CVE-2016-6296</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991437</URL>
        <Description>SUSE Bug 991437</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted zip:// URL.</Note>
    </Notes>
    <CVE>CVE-2016-6297</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-6297.html</URL>
        <Description>CVE-2016-6297</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/991426</URL>
        <Description>SUSE Bug 991426</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads to a (1) __destruct call or (2) magic method call.</Note>
    </Notes>
    <CVE>CVE-2016-7124</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7124.html</URL>
        <Description>CVE-2016-7124</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/997206</URL>
        <Description>SUSE Bug 997206</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as demonstrated by object injection.</Note>
    </Notes>
    <CVE>CVE-2016-7125</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7125.html</URL>
        <Description>CVE-2016-7125</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/997207</URL>
        <Description>SUSE Bug 997207</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate the number of colors, which allows remote attackers to cause a denial of service (select_colors allocation error and out-of-bounds write) or possibly have unspecified other impact via a large value in the third argument.</Note>
    </Notes>
    <CVE>CVE-2016-7126</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7126.html</URL>
        <Description>CVE-2016-7126</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/997208</URL>
        <Description>SUSE Bug 997208</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate gamma values, which allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by providing different signs for the second and third arguments.</Note>
    </Notes>
    <CVE>CVE-2016-7127</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7127.html</URL>
        <Description>CVE-2016-7127</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/997210</URL>
        <Description>SUSE Bug 997210</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that exceeds the file size, which allows remote attackers to obtain sensitive information from process memory via a crafted TIFF image.</Note>
    </Notes>
    <CVE>CVE-2016-7128</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7128.html</URL>
        <Description>CVE-2016-7128</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/997211</URL>
        <Description>SUSE Bug 997211</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via an invalid ISO 8601 time value, as demonstrated by a wddx_deserialize call that mishandles a dateTime element in a wddxPacket XML document.</Note>
    </Notes>
    <CVE>CVE-2016-7129</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7129.html</URL>
        <Description>CVE-2016-7129</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/997220</URL>
        <Description>SUSE Bug 997220</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The php_wddx_pop_element function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid base64 binary value, as demonstrated by a wddx_deserialize call that mishandles a binary element in a wddxPacket XML document.</Note>
    </Notes>
    <CVE>CVE-2016-7130</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7130.html</URL>
        <Description>CVE-2016-7130</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/997257</URL>
        <Description>SUSE Bug 997257</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via a malformed wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a tag that lacks a &lt; (less than) character.</Note>
    </Notes>
    <CVE>CVE-2016-7131</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7131.html</URL>
        <Description>CVE-2016-7131</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/997225</URL>
        <Description>SUSE Bug 997225</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a stray element inside a boolean element, leading to incorrect pop processing.</Note>
    </Notes>
    <CVE>CVE-2016-7132</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7132.html</URL>
        <Description>CVE-2016-7132</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/997230</URL>
        <Description>SUSE Bug 997230</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.</Note>
    </Notes>
    <CVE>CVE-2016-7134</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.1:apache2-mod_php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bcmath-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-bz2-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-calendar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ctype-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-curl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dba-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-devel-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-dom-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-enchant-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-exif-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fastcgi-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fileinfo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-firebird-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-fpm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ftp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gd-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gettext-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-gmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-iconv-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-imap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-intl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-json-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-ldap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mbstring-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mcrypt-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mssql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-mysql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-odbc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-opcache-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-openssl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pcntl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pdo-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pear-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pgsql-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-phar-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-posix-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-pspell-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-readline-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-shmop-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-snmp-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-soap-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sockets-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sqlite-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-suhosin-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvmsg-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvsem-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-sysvshm-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tidy-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-tokenizer-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-wddx-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlreader-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlrpc-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xmlwriter-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-xsl-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zip-5.5.14-59.1</ProductID>
        <ProductID>openSUSE Leap 42.1:php5-zlib-5.5.14-59.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00004.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7134.html</URL>
        <Description>CVE-2016-7134</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/997248</URL>
        <Description>SUSE Bug 997248</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
