<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for php5</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2020:0522-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2020-02-28T08:28:56Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2020-02-28T08:28:56Z</InitialReleaseDate>
    <CurrentReleaseDate>2020-02-28T08:28:56Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for php5</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for php5 fixes the following issues:

Security issues fixed:

- CVE-2019-11041: Fixed heap buffer over-read in exif_scan_thumbnail() (bsc#1146360).
- CVE-2019-11042: Fixed heap buffer over-read in exif_process_user_comment() (bsc#1145095).
- CVE-2019-11043: Fixed possible remote code execution via env_path_info underflow in fpm_main.c (bsc#1154999).
- CVE-2019-11045: Fixed an issue with the PHP DirectoryIterator class that accepts filenames with embedded \0 bytes (bsc#1159923).
- CVE-2019-11046: Fixed an out-of-bounds read in bc_shift_addsub (bsc#1159924).
- CVE-2019-11047: Fixed an information disclosure in exif_read_data (bsc#1159922).
- CVE-2019-11050: Fixed a buffer over-read in the EXIF extension (bsc#1159927).
- CVE-2020-7059: Fixed an out-of-bounds read in php_strip_tags_ex (bsc#1162629).
- CVE-2020-7060: Fixed a global buffer-overflow in mbfl_filt_conv_big5_wchar (bsc#1162632).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2020-522,SUSE-SLE-Module-Web-Scripting-12-2020-522,SUSE-SLE-SDK-12-SP4-2020-522</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20200522-1/</URL>
      <Description>Link for SUSE-SU-2020:0522-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2020-February/006550.html</URL>
      <Description>E-Mail link for SUSE-SU-2020:0522-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1145095</URL>
      <Description>SUSE Bug 1145095</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1146360</URL>
      <Description>SUSE Bug 1146360</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1154999</URL>
      <Description>SUSE Bug 1154999</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1159922</URL>
      <Description>SUSE Bug 1159922</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1159923</URL>
      <Description>SUSE Bug 1159923</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1159924</URL>
      <Description>SUSE Bug 1159924</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1159927</URL>
      <Description>SUSE Bug 1159927</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1161982</URL>
      <Description>SUSE Bug 1161982</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1162629</URL>
      <Description>SUSE Bug 1162629</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1162632</URL>
      <Description>SUSE Bug 1162632</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11041/</URL>
      <Description>SUSE CVE CVE-2019-11041 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11042/</URL>
      <Description>SUSE CVE CVE-2019-11042 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11043/</URL>
      <Description>SUSE CVE CVE-2019-11043 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11045/</URL>
      <Description>SUSE CVE CVE-2019-11045 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11046/</URL>
      <Description>SUSE CVE CVE-2019-11046 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11047/</URL>
      <Description>SUSE CVE CVE-2019-11047 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11050/</URL>
      <Description>SUSE CVE CVE-2019-11050 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-7059/</URL>
      <Description>SUSE CVE CVE-2020-7059 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-7060/</URL>
      <Description>SUSE CVE CVE-2020-7060 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 12 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP4" CPE="cpe:/o:suse:sle-sdk:12:sp4">SUSE Linux Enterprise Software Development Kit 12 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="apache2-mod_php5-5.5.14-109.68.1">
      <FullProductName ProductID="apache2-mod_php5-5.5.14-109.68.1">apache2-mod_php5-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-5.5.14-109.68.1">
      <FullProductName ProductID="php5-5.5.14-109.68.1">php5-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-bcmath-5.5.14-109.68.1">
      <FullProductName ProductID="php5-bcmath-5.5.14-109.68.1">php5-bcmath-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-bz2-5.5.14-109.68.1">
      <FullProductName ProductID="php5-bz2-5.5.14-109.68.1">php5-bz2-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-calendar-5.5.14-109.68.1">
      <FullProductName ProductID="php5-calendar-5.5.14-109.68.1">php5-calendar-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ctype-5.5.14-109.68.1">
      <FullProductName ProductID="php5-ctype-5.5.14-109.68.1">php5-ctype-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-curl-5.5.14-109.68.1">
      <FullProductName ProductID="php5-curl-5.5.14-109.68.1">php5-curl-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-dba-5.5.14-109.68.1">
      <FullProductName ProductID="php5-dba-5.5.14-109.68.1">php5-dba-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-devel-5.5.14-109.68.1">
      <FullProductName ProductID="php5-devel-5.5.14-109.68.1">php5-devel-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-dom-5.5.14-109.68.1">
      <FullProductName ProductID="php5-dom-5.5.14-109.68.1">php5-dom-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-enchant-5.5.14-109.68.1">
      <FullProductName ProductID="php5-enchant-5.5.14-109.68.1">php5-enchant-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-exif-5.5.14-109.68.1">
      <FullProductName ProductID="php5-exif-5.5.14-109.68.1">php5-exif-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fastcgi-5.5.14-109.68.1">
      <FullProductName ProductID="php5-fastcgi-5.5.14-109.68.1">php5-fastcgi-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fileinfo-5.5.14-109.68.1">
      <FullProductName ProductID="php5-fileinfo-5.5.14-109.68.1">php5-fileinfo-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-firebird-5.5.14-109.68.1">
      <FullProductName ProductID="php5-firebird-5.5.14-109.68.1">php5-firebird-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-fpm-5.5.14-109.68.1">
      <FullProductName ProductID="php5-fpm-5.5.14-109.68.1">php5-fpm-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ftp-5.5.14-109.68.1">
      <FullProductName ProductID="php5-ftp-5.5.14-109.68.1">php5-ftp-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gd-5.5.14-109.68.1">
      <FullProductName ProductID="php5-gd-5.5.14-109.68.1">php5-gd-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gettext-5.5.14-109.68.1">
      <FullProductName ProductID="php5-gettext-5.5.14-109.68.1">php5-gettext-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-gmp-5.5.14-109.68.1">
      <FullProductName ProductID="php5-gmp-5.5.14-109.68.1">php5-gmp-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-iconv-5.5.14-109.68.1">
      <FullProductName ProductID="php5-iconv-5.5.14-109.68.1">php5-iconv-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-imap-5.5.14-109.68.1">
      <FullProductName ProductID="php5-imap-5.5.14-109.68.1">php5-imap-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-intl-5.5.14-109.68.1">
      <FullProductName ProductID="php5-intl-5.5.14-109.68.1">php5-intl-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-json-5.5.14-109.68.1">
      <FullProductName ProductID="php5-json-5.5.14-109.68.1">php5-json-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-ldap-5.5.14-109.68.1">
      <FullProductName ProductID="php5-ldap-5.5.14-109.68.1">php5-ldap-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mbstring-5.5.14-109.68.1">
      <FullProductName ProductID="php5-mbstring-5.5.14-109.68.1">php5-mbstring-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mcrypt-5.5.14-109.68.1">
      <FullProductName ProductID="php5-mcrypt-5.5.14-109.68.1">php5-mcrypt-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mssql-5.5.14-109.68.1">
      <FullProductName ProductID="php5-mssql-5.5.14-109.68.1">php5-mssql-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-mysql-5.5.14-109.68.1">
      <FullProductName ProductID="php5-mysql-5.5.14-109.68.1">php5-mysql-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-odbc-5.5.14-109.68.1">
      <FullProductName ProductID="php5-odbc-5.5.14-109.68.1">php5-odbc-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-opcache-5.5.14-109.68.1">
      <FullProductName ProductID="php5-opcache-5.5.14-109.68.1">php5-opcache-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-openssl-5.5.14-109.68.1">
      <FullProductName ProductID="php5-openssl-5.5.14-109.68.1">php5-openssl-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pcntl-5.5.14-109.68.1">
      <FullProductName ProductID="php5-pcntl-5.5.14-109.68.1">php5-pcntl-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pdo-5.5.14-109.68.1">
      <FullProductName ProductID="php5-pdo-5.5.14-109.68.1">php5-pdo-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pear-5.5.14-109.68.1">
      <FullProductName ProductID="php5-pear-5.5.14-109.68.1">php5-pear-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pgsql-5.5.14-109.68.1">
      <FullProductName ProductID="php5-pgsql-5.5.14-109.68.1">php5-pgsql-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-phar-5.5.14-109.68.1">
      <FullProductName ProductID="php5-phar-5.5.14-109.68.1">php5-phar-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-posix-5.5.14-109.68.1">
      <FullProductName ProductID="php5-posix-5.5.14-109.68.1">php5-posix-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-pspell-5.5.14-109.68.1">
      <FullProductName ProductID="php5-pspell-5.5.14-109.68.1">php5-pspell-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-readline-5.5.14-109.68.1">
      <FullProductName ProductID="php5-readline-5.5.14-109.68.1">php5-readline-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-shmop-5.5.14-109.68.1">
      <FullProductName ProductID="php5-shmop-5.5.14-109.68.1">php5-shmop-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-snmp-5.5.14-109.68.1">
      <FullProductName ProductID="php5-snmp-5.5.14-109.68.1">php5-snmp-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-soap-5.5.14-109.68.1">
      <FullProductName ProductID="php5-soap-5.5.14-109.68.1">php5-soap-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sockets-5.5.14-109.68.1">
      <FullProductName ProductID="php5-sockets-5.5.14-109.68.1">php5-sockets-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sqlite-5.5.14-109.68.1">
      <FullProductName ProductID="php5-sqlite-5.5.14-109.68.1">php5-sqlite-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-suhosin-5.5.14-109.68.1">
      <FullProductName ProductID="php5-suhosin-5.5.14-109.68.1">php5-suhosin-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvmsg-5.5.14-109.68.1">
      <FullProductName ProductID="php5-sysvmsg-5.5.14-109.68.1">php5-sysvmsg-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvsem-5.5.14-109.68.1">
      <FullProductName ProductID="php5-sysvsem-5.5.14-109.68.1">php5-sysvsem-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-sysvshm-5.5.14-109.68.1">
      <FullProductName ProductID="php5-sysvshm-5.5.14-109.68.1">php5-sysvshm-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-tidy-5.5.14-109.68.1">
      <FullProductName ProductID="php5-tidy-5.5.14-109.68.1">php5-tidy-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-tokenizer-5.5.14-109.68.1">
      <FullProductName ProductID="php5-tokenizer-5.5.14-109.68.1">php5-tokenizer-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-wddx-5.5.14-109.68.1">
      <FullProductName ProductID="php5-wddx-5.5.14-109.68.1">php5-wddx-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlreader-5.5.14-109.68.1">
      <FullProductName ProductID="php5-xmlreader-5.5.14-109.68.1">php5-xmlreader-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlrpc-5.5.14-109.68.1">
      <FullProductName ProductID="php5-xmlrpc-5.5.14-109.68.1">php5-xmlrpc-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xmlwriter-5.5.14-109.68.1">
      <FullProductName ProductID="php5-xmlwriter-5.5.14-109.68.1">php5-xmlwriter-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-xsl-5.5.14-109.68.1">
      <FullProductName ProductID="php5-xsl-5.5.14-109.68.1">php5-xsl-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-zip-5.5.14-109.68.1">
      <FullProductName ProductID="php5-zip-5.5.14-109.68.1">php5-zip-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php5-zlib-5.5.14-109.68.1">
      <FullProductName ProductID="php5-zlib-5.5.14-109.68.1">php5-zlib-5.5.14-109.68.1</FullProductName>
    </Branch>
    <Relationship ProductReference="apache2-mod_php5-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php5-5.5.14-109.68.1">apache2-mod_php5-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-5.5.14-109.68.1">php5-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-bcmath-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-bcmath-5.5.14-109.68.1">php5-bcmath-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-bz2-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-bz2-5.5.14-109.68.1">php5-bz2-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-calendar-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-calendar-5.5.14-109.68.1">php5-calendar-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ctype-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-ctype-5.5.14-109.68.1">php5-ctype-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-curl-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-curl-5.5.14-109.68.1">php5-curl-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-dba-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-dba-5.5.14-109.68.1">php5-dba-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-dom-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-dom-5.5.14-109.68.1">php5-dom-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-enchant-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-enchant-5.5.14-109.68.1">php5-enchant-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-exif-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-exif-5.5.14-109.68.1">php5-exif-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fastcgi-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-fastcgi-5.5.14-109.68.1">php5-fastcgi-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fileinfo-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-fileinfo-5.5.14-109.68.1">php5-fileinfo-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-fpm-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-fpm-5.5.14-109.68.1">php5-fpm-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ftp-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-ftp-5.5.14-109.68.1">php5-ftp-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gd-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-gd-5.5.14-109.68.1">php5-gd-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gettext-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-gettext-5.5.14-109.68.1">php5-gettext-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-gmp-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-gmp-5.5.14-109.68.1">php5-gmp-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-iconv-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-iconv-5.5.14-109.68.1">php5-iconv-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-imap-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-imap-5.5.14-109.68.1">php5-imap-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-intl-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-intl-5.5.14-109.68.1">php5-intl-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-json-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-json-5.5.14-109.68.1">php5-json-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-ldap-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-ldap-5.5.14-109.68.1">php5-ldap-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mbstring-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-mbstring-5.5.14-109.68.1">php5-mbstring-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mcrypt-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-mcrypt-5.5.14-109.68.1">php5-mcrypt-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-mysql-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-mysql-5.5.14-109.68.1">php5-mysql-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-odbc-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-odbc-5.5.14-109.68.1">php5-odbc-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-opcache-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-opcache-5.5.14-109.68.1">php5-opcache-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-openssl-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-openssl-5.5.14-109.68.1">php5-openssl-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pcntl-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-pcntl-5.5.14-109.68.1">php5-pcntl-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pdo-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-pdo-5.5.14-109.68.1">php5-pdo-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pear-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-pear-5.5.14-109.68.1">php5-pear-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pgsql-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-pgsql-5.5.14-109.68.1">php5-pgsql-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-phar-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-phar-5.5.14-109.68.1">php5-phar-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-posix-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-posix-5.5.14-109.68.1">php5-posix-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-pspell-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-pspell-5.5.14-109.68.1">php5-pspell-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-shmop-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-shmop-5.5.14-109.68.1">php5-shmop-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-snmp-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-snmp-5.5.14-109.68.1">php5-snmp-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-soap-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-soap-5.5.14-109.68.1">php5-soap-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sockets-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-sockets-5.5.14-109.68.1">php5-sockets-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sqlite-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-sqlite-5.5.14-109.68.1">php5-sqlite-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-suhosin-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-suhosin-5.5.14-109.68.1">php5-suhosin-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvmsg-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvmsg-5.5.14-109.68.1">php5-sysvmsg-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvsem-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvsem-5.5.14-109.68.1">php5-sysvsem-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-sysvshm-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvshm-5.5.14-109.68.1">php5-sysvshm-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-tokenizer-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-tokenizer-5.5.14-109.68.1">php5-tokenizer-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-wddx-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-wddx-5.5.14-109.68.1">php5-wddx-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlreader-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlreader-5.5.14-109.68.1">php5-xmlreader-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlrpc-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlrpc-5.5.14-109.68.1">php5-xmlrpc-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xmlwriter-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlwriter-5.5.14-109.68.1">php5-xmlwriter-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-xsl-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-xsl-5.5.14-109.68.1">php5-xsl-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-zip-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-zip-5.5.14-109.68.1">php5-zip-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-zlib-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php5-zlib-5.5.14-109.68.1">php5-zlib-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php5-devel-5.5.14-109.68.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP4:php5-devel-5.5.14-109.68.1">php5-devel-5.5.14-109.68.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP4</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11041</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bcmath-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bz2-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-calendar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ctype-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-curl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dba-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dom-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-enchant-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-exif-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fastcgi-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fileinfo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fpm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ftp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gd-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gettext-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-iconv-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-imap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-intl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-json-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ldap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mbstring-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mcrypt-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mysql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-odbc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-opcache-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-openssl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pcntl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pdo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pear-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pgsql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-phar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-posix-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pspell-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-shmop-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-snmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-soap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sockets-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sqlite-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-suhosin-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvmsg-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvsem-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvshm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-tokenizer-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-wddx-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlreader-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlrpc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlwriter-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xsl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zip-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zlib-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP4:php5-devel-5.5.14-109.68.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20200522-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11041.html</URL>
        <Description>CVE-2019-11041</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1146360</URL>
        <Description>SUSE Bug 1146360</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11042</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bcmath-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bz2-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-calendar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ctype-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-curl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dba-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dom-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-enchant-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-exif-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fastcgi-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fileinfo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fpm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ftp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gd-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gettext-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-iconv-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-imap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-intl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-json-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ldap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mbstring-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mcrypt-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mysql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-odbc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-opcache-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-openssl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pcntl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pdo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pear-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pgsql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-phar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-posix-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pspell-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-shmop-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-snmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-soap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sockets-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sqlite-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-suhosin-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvmsg-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvsem-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvshm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-tokenizer-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-wddx-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlreader-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlrpc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlwriter-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xsl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zip-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zlib-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP4:php5-devel-5.5.14-109.68.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20200522-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11042.html</URL>
        <Description>CVE-2019-11042</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1145095</URL>
        <Description>SUSE Bug 1145095</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.</Note>
    </Notes>
    <CVE>CVE-2019-11043</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bcmath-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bz2-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-calendar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ctype-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-curl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dba-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dom-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-enchant-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-exif-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fastcgi-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fileinfo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fpm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ftp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gd-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gettext-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-iconv-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-imap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-intl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-json-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ldap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mbstring-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mcrypt-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mysql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-odbc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-opcache-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-openssl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pcntl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pdo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pear-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pgsql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-phar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-posix-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pspell-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-shmop-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-snmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-soap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sockets-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sqlite-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-suhosin-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvmsg-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvsem-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvshm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-tokenizer-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-wddx-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlreader-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlrpc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlwriter-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xsl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zip-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zlib-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP4:php5-devel-5.5.14-109.68.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20200522-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11043.html</URL>
        <Description>CVE-2019-11043</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1154999</URL>
        <Description>SUSE Bug 1154999</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.</Note>
    </Notes>
    <CVE>CVE-2019-11045</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bcmath-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bz2-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-calendar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ctype-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-curl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dba-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dom-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-enchant-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-exif-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fastcgi-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fileinfo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fpm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ftp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gd-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gettext-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-iconv-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-imap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-intl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-json-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ldap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mbstring-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mcrypt-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mysql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-odbc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-opcache-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-openssl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pcntl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pdo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pear-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pgsql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-phar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-posix-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pspell-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-shmop-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-snmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-soap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sockets-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sqlite-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-suhosin-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvmsg-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvsem-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvshm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-tokenizer-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-wddx-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlreader-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlrpc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlwriter-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xsl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zip-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zlib-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP4:php5-devel-5.5.14-109.68.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20200522-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11045.html</URL>
        <Description>CVE-2019-11045</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159923</URL>
        <Description>SUSE Bug 1159923</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.</Note>
    </Notes>
    <CVE>CVE-2019-11046</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bcmath-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bz2-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-calendar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ctype-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-curl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dba-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dom-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-enchant-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-exif-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fastcgi-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fileinfo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fpm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ftp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gd-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gettext-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-iconv-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-imap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-intl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-json-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ldap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mbstring-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mcrypt-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mysql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-odbc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-opcache-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-openssl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pcntl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pdo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pear-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pgsql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-phar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-posix-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pspell-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-shmop-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-snmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-soap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sockets-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sqlite-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-suhosin-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvmsg-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvsem-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvshm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-tokenizer-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-wddx-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlreader-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlrpc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlwriter-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xsl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zip-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zlib-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP4:php5-devel-5.5.14-109.68.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20200522-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11046.html</URL>
        <Description>CVE-2019-11046</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159924</URL>
        <Description>SUSE Bug 1159924</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11047</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bcmath-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bz2-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-calendar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ctype-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-curl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dba-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dom-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-enchant-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-exif-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fastcgi-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fileinfo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fpm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ftp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gd-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gettext-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-iconv-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-imap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-intl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-json-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ldap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mbstring-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mcrypt-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mysql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-odbc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-opcache-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-openssl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pcntl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pdo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pear-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pgsql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-phar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-posix-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pspell-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-shmop-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-snmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-soap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sockets-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sqlite-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-suhosin-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvmsg-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvsem-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvshm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-tokenizer-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-wddx-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlreader-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlrpc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlwriter-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xsl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zip-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zlib-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP4:php5-devel-5.5.14-109.68.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20200522-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11047.html</URL>
        <Description>CVE-2019-11047</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159922</URL>
        <Description>SUSE Bug 1159922</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11050</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bcmath-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bz2-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-calendar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ctype-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-curl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dba-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dom-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-enchant-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-exif-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fastcgi-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fileinfo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fpm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ftp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gd-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gettext-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-iconv-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-imap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-intl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-json-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ldap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mbstring-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mcrypt-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mysql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-odbc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-opcache-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-openssl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pcntl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pdo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pear-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pgsql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-phar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-posix-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pspell-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-shmop-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-snmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-soap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sockets-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sqlite-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-suhosin-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvmsg-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvsem-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvshm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-tokenizer-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-wddx-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlreader-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlrpc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlwriter-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xsl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zip-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zlib-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP4:php5-devel-5.5.14-109.68.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20200522-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11050.html</URL>
        <Description>CVE-2019-11050</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159927</URL>
        <Description>SUSE Bug 1159927</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2020-7059</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bcmath-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bz2-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-calendar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ctype-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-curl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dba-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dom-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-enchant-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-exif-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fastcgi-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fileinfo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fpm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ftp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gd-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gettext-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-iconv-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-imap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-intl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-json-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ldap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mbstring-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mcrypt-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mysql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-odbc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-opcache-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-openssl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pcntl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pdo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pear-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pgsql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-phar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-posix-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pspell-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-shmop-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-snmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-soap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sockets-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sqlite-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-suhosin-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvmsg-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvsem-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvshm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-tokenizer-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-wddx-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlreader-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlrpc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlwriter-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xsl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zip-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zlib-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP4:php5-devel-5.5.14-109.68.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20200522-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-7059.html</URL>
        <Description>CVE-2020-7059</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1162629</URL>
        <Description>SUSE Bug 1162629</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big5_wchar to read past the allocated buffer. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2020-7060</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bcmath-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-bz2-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-calendar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ctype-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-curl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dba-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-dom-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-enchant-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-exif-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fastcgi-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fileinfo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-fpm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ftp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gd-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gettext-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-gmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-iconv-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-imap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-intl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-json-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-ldap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mbstring-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mcrypt-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-mysql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-odbc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-opcache-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-openssl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pcntl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pdo-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pear-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pgsql-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-phar-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-posix-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-pspell-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-shmop-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-snmp-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-soap-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sockets-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sqlite-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-suhosin-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvmsg-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvsem-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvshm-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-tokenizer-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-wddx-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlreader-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlrpc-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlwriter-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-xsl-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zip-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php5-zlib-5.5.14-109.68.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP4:php5-devel-5.5.14-109.68.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20200522-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-7060.html</URL>
        <Description>CVE-2020-7060</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1162632</URL>
        <Description>SUSE Bug 1162632</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
