<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for php7</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2019:1725-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2019-07-02T14:50:26Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2019-07-02T14:50:26Z</InitialReleaseDate>
    <CurrentReleaseDate>2019-07-02T14:50:26Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for php7</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for php7 fixes the following issues:
	  
Security issues fixed:	  

- CVE-2019-11039: Fixed a heap-buffer-overflow on php_jpg_get16 (bsc#1138173).
- CVE-2019-11040: Fixed an out-of-bounds read due to an integer overflow in 
  iconv.c:_php_iconv_mime_decode() (bsc#1138172).
    
Other issue addressed: 
 
- Enable php7 testsuite (bsc#1119396   
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2019-1725,SUSE-SLE-Module-Web-Scripting-12-2019-1725,SUSE-SLE-SDK-12-SP3-2019-1725,SUSE-SLE-SDK-12-SP4-2019-1725</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2019/suse-su-20191725-1/</URL>
      <Description>Link for SUSE-SU-2019:1725-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2019-July/005648.html</URL>
      <Description>E-Mail link for SUSE-SU-2019:1725-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1119396</URL>
      <Description>SUSE Bug 1119396</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1138172</URL>
      <Description>SUSE Bug 1138172</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1138173</URL>
      <Description>SUSE Bug 1138173</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11039/</URL>
      <Description>SUSE CVE CVE-2019-11039 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11040/</URL>
      <Description>SUSE CVE CVE-2019-11040 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 12 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP3" CPE="cpe:/o:suse:sle-sdk:12:sp3">SUSE Linux Enterprise Software Development Kit 12 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 12 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP4" CPE="cpe:/o:suse:sle-sdk:12:sp4">SUSE Linux Enterprise Software Development Kit 12 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="apache2-mod_php7-7.0.7-50.80.2">
      <FullProductName ProductID="apache2-mod_php7-7.0.7-50.80.2">apache2-mod_php7-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-7.0.7-50.80.2">
      <FullProductName ProductID="php7-7.0.7-50.80.2">php7-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-bcmath-7.0.7-50.80.2">
      <FullProductName ProductID="php7-bcmath-7.0.7-50.80.2">php7-bcmath-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-bz2-7.0.7-50.80.2">
      <FullProductName ProductID="php7-bz2-7.0.7-50.80.2">php7-bz2-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-calendar-7.0.7-50.80.2">
      <FullProductName ProductID="php7-calendar-7.0.7-50.80.2">php7-calendar-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ctype-7.0.7-50.80.2">
      <FullProductName ProductID="php7-ctype-7.0.7-50.80.2">php7-ctype-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-curl-7.0.7-50.80.2">
      <FullProductName ProductID="php7-curl-7.0.7-50.80.2">php7-curl-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-dba-7.0.7-50.80.2">
      <FullProductName ProductID="php7-dba-7.0.7-50.80.2">php7-dba-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-devel-7.0.7-50.80.2">
      <FullProductName ProductID="php7-devel-7.0.7-50.80.2">php7-devel-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-dom-7.0.7-50.80.2">
      <FullProductName ProductID="php7-dom-7.0.7-50.80.2">php7-dom-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-enchant-7.0.7-50.80.2">
      <FullProductName ProductID="php7-enchant-7.0.7-50.80.2">php7-enchant-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-exif-7.0.7-50.80.2">
      <FullProductName ProductID="php7-exif-7.0.7-50.80.2">php7-exif-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fastcgi-7.0.7-50.80.2">
      <FullProductName ProductID="php7-fastcgi-7.0.7-50.80.2">php7-fastcgi-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fileinfo-7.0.7-50.80.2">
      <FullProductName ProductID="php7-fileinfo-7.0.7-50.80.2">php7-fileinfo-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-firebird-7.0.7-50.80.2">
      <FullProductName ProductID="php7-firebird-7.0.7-50.80.2">php7-firebird-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fpm-7.0.7-50.80.2">
      <FullProductName ProductID="php7-fpm-7.0.7-50.80.2">php7-fpm-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ftp-7.0.7-50.80.2">
      <FullProductName ProductID="php7-ftp-7.0.7-50.80.2">php7-ftp-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gd-7.0.7-50.80.2">
      <FullProductName ProductID="php7-gd-7.0.7-50.80.2">php7-gd-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gettext-7.0.7-50.80.2">
      <FullProductName ProductID="php7-gettext-7.0.7-50.80.2">php7-gettext-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gmp-7.0.7-50.80.2">
      <FullProductName ProductID="php7-gmp-7.0.7-50.80.2">php7-gmp-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-iconv-7.0.7-50.80.2">
      <FullProductName ProductID="php7-iconv-7.0.7-50.80.2">php7-iconv-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-imap-7.0.7-50.80.2">
      <FullProductName ProductID="php7-imap-7.0.7-50.80.2">php7-imap-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-intl-7.0.7-50.80.2">
      <FullProductName ProductID="php7-intl-7.0.7-50.80.2">php7-intl-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-json-7.0.7-50.80.2">
      <FullProductName ProductID="php7-json-7.0.7-50.80.2">php7-json-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ldap-7.0.7-50.80.2">
      <FullProductName ProductID="php7-ldap-7.0.7-50.80.2">php7-ldap-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-mbstring-7.0.7-50.80.2">
      <FullProductName ProductID="php7-mbstring-7.0.7-50.80.2">php7-mbstring-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-mcrypt-7.0.7-50.80.2">
      <FullProductName ProductID="php7-mcrypt-7.0.7-50.80.2">php7-mcrypt-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-mysql-7.0.7-50.80.2">
      <FullProductName ProductID="php7-mysql-7.0.7-50.80.2">php7-mysql-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-odbc-7.0.7-50.80.2">
      <FullProductName ProductID="php7-odbc-7.0.7-50.80.2">php7-odbc-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-opcache-7.0.7-50.80.2">
      <FullProductName ProductID="php7-opcache-7.0.7-50.80.2">php7-opcache-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-openssl-7.0.7-50.80.2">
      <FullProductName ProductID="php7-openssl-7.0.7-50.80.2">php7-openssl-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pcntl-7.0.7-50.80.2">
      <FullProductName ProductID="php7-pcntl-7.0.7-50.80.2">php7-pcntl-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pdo-7.0.7-50.80.2">
      <FullProductName ProductID="php7-pdo-7.0.7-50.80.2">php7-pdo-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pear-7.0.7-50.80.2">
      <FullProductName ProductID="php7-pear-7.0.7-50.80.2">php7-pear-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pear-Archive_Tar-7.0.7-50.80.2">
      <FullProductName ProductID="php7-pear-Archive_Tar-7.0.7-50.80.2">php7-pear-Archive_Tar-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pgsql-7.0.7-50.80.2">
      <FullProductName ProductID="php7-pgsql-7.0.7-50.80.2">php7-pgsql-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-phar-7.0.7-50.80.2">
      <FullProductName ProductID="php7-phar-7.0.7-50.80.2">php7-phar-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-posix-7.0.7-50.80.2">
      <FullProductName ProductID="php7-posix-7.0.7-50.80.2">php7-posix-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pspell-7.0.7-50.80.2">
      <FullProductName ProductID="php7-pspell-7.0.7-50.80.2">php7-pspell-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-readline-7.0.7-50.80.2">
      <FullProductName ProductID="php7-readline-7.0.7-50.80.2">php7-readline-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-shmop-7.0.7-50.80.2">
      <FullProductName ProductID="php7-shmop-7.0.7-50.80.2">php7-shmop-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-snmp-7.0.7-50.80.2">
      <FullProductName ProductID="php7-snmp-7.0.7-50.80.2">php7-snmp-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-soap-7.0.7-50.80.2">
      <FullProductName ProductID="php7-soap-7.0.7-50.80.2">php7-soap-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sockets-7.0.7-50.80.2">
      <FullProductName ProductID="php7-sockets-7.0.7-50.80.2">php7-sockets-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sqlite-7.0.7-50.80.2">
      <FullProductName ProductID="php7-sqlite-7.0.7-50.80.2">php7-sqlite-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvmsg-7.0.7-50.80.2">
      <FullProductName ProductID="php7-sysvmsg-7.0.7-50.80.2">php7-sysvmsg-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvsem-7.0.7-50.80.2">
      <FullProductName ProductID="php7-sysvsem-7.0.7-50.80.2">php7-sysvsem-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvshm-7.0.7-50.80.2">
      <FullProductName ProductID="php7-sysvshm-7.0.7-50.80.2">php7-sysvshm-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-testresults-7.0.7-50.80.2">
      <FullProductName ProductID="php7-testresults-7.0.7-50.80.2">php7-testresults-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-tidy-7.0.7-50.80.2">
      <FullProductName ProductID="php7-tidy-7.0.7-50.80.2">php7-tidy-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-tokenizer-7.0.7-50.80.2">
      <FullProductName ProductID="php7-tokenizer-7.0.7-50.80.2">php7-tokenizer-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-wddx-7.0.7-50.80.2">
      <FullProductName ProductID="php7-wddx-7.0.7-50.80.2">php7-wddx-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlreader-7.0.7-50.80.2">
      <FullProductName ProductID="php7-xmlreader-7.0.7-50.80.2">php7-xmlreader-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlrpc-7.0.7-50.80.2">
      <FullProductName ProductID="php7-xmlrpc-7.0.7-50.80.2">php7-xmlrpc-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlwriter-7.0.7-50.80.2">
      <FullProductName ProductID="php7-xmlwriter-7.0.7-50.80.2">php7-xmlwriter-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xsl-7.0.7-50.80.2">
      <FullProductName ProductID="php7-xsl-7.0.7-50.80.2">php7-xsl-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-zip-7.0.7-50.80.2">
      <FullProductName ProductID="php7-zip-7.0.7-50.80.2">php7-zip-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-zlib-7.0.7-50.80.2">
      <FullProductName ProductID="php7-zlib-7.0.7-50.80.2">php7-zlib-7.0.7-50.80.2</FullProductName>
    </Branch>
    <Relationship ProductReference="apache2-mod_php7-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php7-7.0.7-50.80.2">apache2-mod_php7-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-7.0.7-50.80.2">php7-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-bcmath-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-bcmath-7.0.7-50.80.2">php7-bcmath-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-bz2-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-bz2-7.0.7-50.80.2">php7-bz2-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-calendar-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-calendar-7.0.7-50.80.2">php7-calendar-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ctype-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-ctype-7.0.7-50.80.2">php7-ctype-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-curl-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-curl-7.0.7-50.80.2">php7-curl-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-dba-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-dba-7.0.7-50.80.2">php7-dba-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-dom-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-dom-7.0.7-50.80.2">php7-dom-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-enchant-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-enchant-7.0.7-50.80.2">php7-enchant-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-exif-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-exif-7.0.7-50.80.2">php7-exif-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fastcgi-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-fastcgi-7.0.7-50.80.2">php7-fastcgi-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fileinfo-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-fileinfo-7.0.7-50.80.2">php7-fileinfo-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fpm-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-fpm-7.0.7-50.80.2">php7-fpm-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ftp-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-ftp-7.0.7-50.80.2">php7-ftp-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gd-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-gd-7.0.7-50.80.2">php7-gd-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gettext-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-gettext-7.0.7-50.80.2">php7-gettext-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gmp-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-gmp-7.0.7-50.80.2">php7-gmp-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-iconv-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-iconv-7.0.7-50.80.2">php7-iconv-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-imap-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-imap-7.0.7-50.80.2">php7-imap-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-intl-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-intl-7.0.7-50.80.2">php7-intl-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-json-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-json-7.0.7-50.80.2">php7-json-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ldap-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-ldap-7.0.7-50.80.2">php7-ldap-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-mbstring-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-mbstring-7.0.7-50.80.2">php7-mbstring-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-mcrypt-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-mcrypt-7.0.7-50.80.2">php7-mcrypt-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-mysql-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-mysql-7.0.7-50.80.2">php7-mysql-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-odbc-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-odbc-7.0.7-50.80.2">php7-odbc-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-opcache-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-opcache-7.0.7-50.80.2">php7-opcache-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-openssl-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-openssl-7.0.7-50.80.2">php7-openssl-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pcntl-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-pcntl-7.0.7-50.80.2">php7-pcntl-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pdo-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-pdo-7.0.7-50.80.2">php7-pdo-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pear-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-pear-7.0.7-50.80.2">php7-pear-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pear-Archive_Tar-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-pear-Archive_Tar-7.0.7-50.80.2">php7-pear-Archive_Tar-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pgsql-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-pgsql-7.0.7-50.80.2">php7-pgsql-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-phar-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-phar-7.0.7-50.80.2">php7-phar-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-posix-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-posix-7.0.7-50.80.2">php7-posix-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pspell-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-pspell-7.0.7-50.80.2">php7-pspell-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-shmop-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-shmop-7.0.7-50.80.2">php7-shmop-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-snmp-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-snmp-7.0.7-50.80.2">php7-snmp-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-soap-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-soap-7.0.7-50.80.2">php7-soap-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sockets-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-sockets-7.0.7-50.80.2">php7-sockets-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sqlite-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-sqlite-7.0.7-50.80.2">php7-sqlite-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvmsg-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-sysvmsg-7.0.7-50.80.2">php7-sysvmsg-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvsem-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-sysvsem-7.0.7-50.80.2">php7-sysvsem-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvshm-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-sysvshm-7.0.7-50.80.2">php7-sysvshm-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-tokenizer-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-tokenizer-7.0.7-50.80.2">php7-tokenizer-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-wddx-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-wddx-7.0.7-50.80.2">php7-wddx-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlreader-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-xmlreader-7.0.7-50.80.2">php7-xmlreader-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlrpc-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-xmlrpc-7.0.7-50.80.2">php7-xmlrpc-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlwriter-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-xmlwriter-7.0.7-50.80.2">php7-xmlwriter-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xsl-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-xsl-7.0.7-50.80.2">php7-xsl-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-zip-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-zip-7.0.7-50.80.2">php7-zip-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-zlib-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php7-zlib-7.0.7-50.80.2">php7-zlib-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-devel-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP3:php7-devel-7.0.7-50.80.2">php7-devel-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Software Development Kit 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-devel-7.0.7-50.80.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP4:php7-devel-7.0.7-50.80.2">php7-devel-7.0.7-50.80.2 as a component of SUSE Linux Enterprise Software Development Kit 12 SP4</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11039</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php7-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-bcmath-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-bz2-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-calendar-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-ctype-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-curl-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-dba-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-dom-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-enchant-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-exif-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-fastcgi-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-fileinfo-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-fpm-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-ftp-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-gd-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-gettext-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-gmp-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-iconv-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-imap-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-intl-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-json-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-ldap-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-mbstring-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-mcrypt-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-mysql-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-odbc-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-opcache-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-openssl-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pcntl-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pdo-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pear-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pear-Archive_Tar-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pgsql-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-phar-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-posix-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pspell-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-shmop-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-snmp-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-soap-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-sockets-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-sqlite-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-sysvmsg-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-sysvsem-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-sysvshm-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-tokenizer-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-wddx-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-xmlreader-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-xmlrpc-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-xmlwriter-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-xsl-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-zip-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-zlib-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:php7-devel-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP4:php7-devel-7.0.7-50.80.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2019/suse-su-20191725-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11039.html</URL>
        <Description>CVE-2019-11039</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1138173</URL>
        <Description>SUSE Bug 1138173</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11040</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php7-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-bcmath-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-bz2-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-calendar-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-ctype-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-curl-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-dba-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-dom-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-enchant-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-exif-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-fastcgi-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-fileinfo-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-fpm-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-ftp-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-gd-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-gettext-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-gmp-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-iconv-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-imap-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-intl-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-json-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-ldap-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-mbstring-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-mcrypt-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-mysql-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-odbc-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-opcache-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-openssl-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pcntl-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pdo-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pear-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pear-Archive_Tar-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pgsql-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-phar-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-posix-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-pspell-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-shmop-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-snmp-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-soap-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-sockets-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-sqlite-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-sysvmsg-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-sysvsem-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-sysvshm-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-tokenizer-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-wddx-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-xmlreader-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-xmlrpc-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-xmlwriter-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-xsl-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-zip-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php7-zlib-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:php7-devel-7.0.7-50.80.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP4:php7-devel-7.0.7-50.80.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2019/suse-su-20191725-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11040.html</URL>
        <Description>CVE-2019-11040</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1138172</URL>
        <Description>SUSE Bug 1138172</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
