<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for php7</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2019:1573-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2019-06-18T11:38:13Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2019-06-18T11:38:13Z</InitialReleaseDate>
    <CurrentReleaseDate>2019-06-18T11:38:13Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for php7</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for php7 fixes the following issues:

Security issues fixed:

- CVE-2019-9637: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128892).
- CVE-2019-9675: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128886).
- CVE-2019-9638: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension ((bsc#1128889).
- CVE-2019-9639: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128887).
- CVE-2019-9640: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128883).
- CVE-2019-9022: Fixed a vulnerability which could allow a hostile DNS server to make PHP misuse memcpy (bsc#1126827).
- CVE-2019-9024: Fixed a vulnerability in xmlrpc_decode function which could allow to a hostile XMLRPC server
  to cause memory read outside the allocated areas (bsc#1126821).
- CVE-2019-9020: Fixed a heap out of bounds in xmlrpc_decode function (bsc#1126711).
- CVE-2018-20783: Fixed a buffer over-read in PHAR reading functions which could allow an attacker to read
  allocated and unallocated memory when parsing a phar file (bsc#1127122).
- CVE-2019-9021: Fixed a heap buffer-based buffer over-read in PHAR reading functions which could allow an
  attacker to read allocated and unallocated memory when parsing a phar file (bsc#1126713).
- CVE-2019-9023: Fixed multiple heap-based buffer over-read instances in mbstring regular expression functions (bsc#1126823).
- CVE-2019-9641: Fixed multiple invalid memory access in EXIF extension and improved insecure implementation
  of rename function (bsc#1128722).
- CVE-2018-19935: Fixed a Denial of Service in php_imap.c which could be triggered 
  via an empty string in the message argument to imap_mail (bsc#1118832).
- CVE-2019-11034: Fixed a heap-buffer overflow in php_ifd_get32si() (bsc#1132838).
- CVE-2019-11035: Fixed a heap-buffer overflow in exif_iif_add_value() (bsc#1132837).
- CVE-2019-11036: Fixed buffer over-read in exif_process_IFD_TAG function leading to information disclosure (bsc#1134322).

Other issue addressed:   

- Deleted README.default_socket_timeout which is not needed anymore (bsc#1129032).
- Enabled php7 testsuite (bsc#1119396).

This update was imported from the SUSE:SLE-15:Update update project.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2019-1573</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      <Description>E-Mail link for openSUSE-SU-2019:1573-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1118832</URL>
      <Description>SUSE Bug 1118832</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1119396</URL>
      <Description>SUSE Bug 1119396</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1126711</URL>
      <Description>SUSE Bug 1126711</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1126713</URL>
      <Description>SUSE Bug 1126713</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1126821</URL>
      <Description>SUSE Bug 1126821</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1126823</URL>
      <Description>SUSE Bug 1126823</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1126827</URL>
      <Description>SUSE Bug 1126827</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1127122</URL>
      <Description>SUSE Bug 1127122</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1128722</URL>
      <Description>SUSE Bug 1128722</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1128883</URL>
      <Description>SUSE Bug 1128883</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1128886</URL>
      <Description>SUSE Bug 1128886</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1128887</URL>
      <Description>SUSE Bug 1128887</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1128889</URL>
      <Description>SUSE Bug 1128889</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1128892</URL>
      <Description>SUSE Bug 1128892</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1129032</URL>
      <Description>SUSE Bug 1129032</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1132837</URL>
      <Description>SUSE Bug 1132837</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1132838</URL>
      <Description>SUSE Bug 1132838</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1134322</URL>
      <Description>SUSE Bug 1134322</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-19935/</URL>
      <Description>SUSE CVE CVE-2018-19935 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-20783/</URL>
      <Description>SUSE CVE CVE-2018-20783 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11034/</URL>
      <Description>SUSE CVE CVE-2019-11034 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11035/</URL>
      <Description>SUSE CVE CVE-2019-11035 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11036/</URL>
      <Description>SUSE CVE CVE-2019-11036 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9020/</URL>
      <Description>SUSE CVE CVE-2019-9020 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9021/</URL>
      <Description>SUSE CVE CVE-2019-9021 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9022/</URL>
      <Description>SUSE CVE CVE-2019-9022 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9023/</URL>
      <Description>SUSE CVE CVE-2019-9023 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9024/</URL>
      <Description>SUSE CVE CVE-2019-9024 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9637/</URL>
      <Description>SUSE CVE CVE-2019-9637 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9638/</URL>
      <Description>SUSE CVE CVE-2019-9638 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9639/</URL>
      <Description>SUSE CVE CVE-2019-9639 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9640/</URL>
      <Description>SUSE CVE CVE-2019-9640 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9641/</URL>
      <Description>SUSE CVE CVE-2019-9641 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9675/</URL>
      <Description>SUSE CVE CVE-2019-9675 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 15.0">
      <Branch Type="Product Name" Name="openSUSE Leap 15.0">
        <FullProductName ProductID="openSUSE Leap 15.0" CPE="cpe:/o:opensuse:leap:15.0">openSUSE Leap 15.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="apache2-mod_php7-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="apache2-mod_php7-7.2.5-lp150.2.19.1">apache2-mod_php7-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-7.2.5-lp150.2.19.1">php7-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-bcmath-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-bcmath-7.2.5-lp150.2.19.1">php7-bcmath-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-bz2-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-bz2-7.2.5-lp150.2.19.1">php7-bz2-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-calendar-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-calendar-7.2.5-lp150.2.19.1">php7-calendar-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ctype-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-ctype-7.2.5-lp150.2.19.1">php7-ctype-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-curl-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-curl-7.2.5-lp150.2.19.1">php7-curl-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-dba-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-dba-7.2.5-lp150.2.19.1">php7-dba-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-devel-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-devel-7.2.5-lp150.2.19.1">php7-devel-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-dom-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-dom-7.2.5-lp150.2.19.1">php7-dom-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-embed-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-embed-7.2.5-lp150.2.19.1">php7-embed-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-enchant-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-enchant-7.2.5-lp150.2.19.1">php7-enchant-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-exif-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-exif-7.2.5-lp150.2.19.1">php7-exif-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fastcgi-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-fastcgi-7.2.5-lp150.2.19.1">php7-fastcgi-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fileinfo-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-fileinfo-7.2.5-lp150.2.19.1">php7-fileinfo-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-firebird-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-firebird-7.2.5-lp150.2.19.1">php7-firebird-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fpm-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-fpm-7.2.5-lp150.2.19.1">php7-fpm-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ftp-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-ftp-7.2.5-lp150.2.19.1">php7-ftp-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gd-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-gd-7.2.5-lp150.2.19.1">php7-gd-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gettext-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-gettext-7.2.5-lp150.2.19.1">php7-gettext-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gmp-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-gmp-7.2.5-lp150.2.19.1">php7-gmp-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-iconv-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-iconv-7.2.5-lp150.2.19.1">php7-iconv-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-intl-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-intl-7.2.5-lp150.2.19.1">php7-intl-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-json-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-json-7.2.5-lp150.2.19.1">php7-json-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ldap-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-ldap-7.2.5-lp150.2.19.1">php7-ldap-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-mbstring-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-mbstring-7.2.5-lp150.2.19.1">php7-mbstring-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-mysql-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-mysql-7.2.5-lp150.2.19.1">php7-mysql-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-odbc-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-odbc-7.2.5-lp150.2.19.1">php7-odbc-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-opcache-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-opcache-7.2.5-lp150.2.19.1">php7-opcache-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-openssl-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-openssl-7.2.5-lp150.2.19.1">php7-openssl-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pcntl-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-pcntl-7.2.5-lp150.2.19.1">php7-pcntl-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pdo-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-pdo-7.2.5-lp150.2.19.1">php7-pdo-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pear-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-pear-7.2.5-lp150.2.19.1">php7-pear-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pear-Archive_Tar-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-pear-Archive_Tar-7.2.5-lp150.2.19.1">php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pgsql-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-pgsql-7.2.5-lp150.2.19.1">php7-pgsql-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-phar-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-phar-7.2.5-lp150.2.19.1">php7-phar-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-posix-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-posix-7.2.5-lp150.2.19.1">php7-posix-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-readline-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-readline-7.2.5-lp150.2.19.1">php7-readline-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-shmop-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-shmop-7.2.5-lp150.2.19.1">php7-shmop-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-snmp-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-snmp-7.2.5-lp150.2.19.1">php7-snmp-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-soap-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-soap-7.2.5-lp150.2.19.1">php7-soap-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sockets-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-sockets-7.2.5-lp150.2.19.1">php7-sockets-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sodium-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-sodium-7.2.5-lp150.2.19.1">php7-sodium-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sqlite-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-sqlite-7.2.5-lp150.2.19.1">php7-sqlite-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvmsg-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-sysvmsg-7.2.5-lp150.2.19.1">php7-sysvmsg-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvsem-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-sysvsem-7.2.5-lp150.2.19.1">php7-sysvsem-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvshm-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-sysvshm-7.2.5-lp150.2.19.1">php7-sysvshm-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-testresults-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-testresults-7.2.5-lp150.2.19.1">php7-testresults-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-tidy-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-tidy-7.2.5-lp150.2.19.1">php7-tidy-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-tokenizer-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-tokenizer-7.2.5-lp150.2.19.1">php7-tokenizer-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-wddx-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-wddx-7.2.5-lp150.2.19.1">php7-wddx-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlreader-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-xmlreader-7.2.5-lp150.2.19.1">php7-xmlreader-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlrpc-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-xmlrpc-7.2.5-lp150.2.19.1">php7-xmlrpc-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlwriter-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-xmlwriter-7.2.5-lp150.2.19.1">php7-xmlwriter-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xsl-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-xsl-7.2.5-lp150.2.19.1">php7-xsl-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-zip-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-zip-7.2.5-lp150.2.19.1">php7-zip-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-zlib-7.2.5-lp150.2.19.1">
      <FullProductName ProductID="php7-zlib-7.2.5-lp150.2.19.1">php7-zlib-7.2.5-lp150.2.19.1</FullProductName>
    </Branch>
    <Relationship ProductReference="apache2-mod_php7-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1">apache2-mod_php7-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1">php7-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-bcmath-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1">php7-bcmath-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-bz2-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1">php7-bz2-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-calendar-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1">php7-calendar-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ctype-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1">php7-ctype-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-curl-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1">php7-curl-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-dba-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1">php7-dba-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-devel-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1">php7-devel-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-dom-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1">php7-dom-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-embed-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1">php7-embed-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-enchant-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1">php7-enchant-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-exif-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1">php7-exif-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fastcgi-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1">php7-fastcgi-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fileinfo-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1">php7-fileinfo-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-firebird-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1">php7-firebird-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fpm-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1">php7-fpm-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ftp-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1">php7-ftp-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gd-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1">php7-gd-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gettext-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1">php7-gettext-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gmp-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1">php7-gmp-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-iconv-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1">php7-iconv-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-intl-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1">php7-intl-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-json-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1">php7-json-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ldap-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1">php7-ldap-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-mbstring-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1">php7-mbstring-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-mysql-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1">php7-mysql-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-odbc-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1">php7-odbc-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-opcache-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1">php7-opcache-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-openssl-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1">php7-openssl-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pcntl-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1">php7-pcntl-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pdo-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1">php7-pdo-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pear-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1">php7-pear-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pear-Archive_Tar-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1">php7-pear-Archive_Tar-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pgsql-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1">php7-pgsql-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-phar-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1">php7-phar-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-posix-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1">php7-posix-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-readline-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1">php7-readline-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-shmop-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1">php7-shmop-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-snmp-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1">php7-snmp-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-soap-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1">php7-soap-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sockets-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1">php7-sockets-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sodium-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1">php7-sodium-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sqlite-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1">php7-sqlite-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvmsg-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1">php7-sysvmsg-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvsem-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1">php7-sysvsem-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvshm-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1">php7-sysvshm-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-testresults-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1">php7-testresults-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-tidy-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1">php7-tidy-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-tokenizer-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1">php7-tokenizer-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-wddx-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1">php7-wddx-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlreader-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1">php7-xmlreader-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlrpc-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1">php7-xmlrpc-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlwriter-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1">php7-xmlwriter-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xsl-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1">php7-xsl-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-zip-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1">php7-zip-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-zlib-7.2.5-lp150.2.19.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.0">
      <FullProductName ProductID="openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1">php7-zlib-7.2.5-lp150.2.19.1 as a component of openSUSE Leap 15.0</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty string in the message argument to the imap_mail function.</Note>
    </Notes>
    <CVE>CVE-2018-19935</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-19935.html</URL>
        <Description>CVE-2018-19935</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1118832</URL>
        <Description>SUSE Bug 1118832</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.</Note>
    </Notes>
    <CVE>CVE-2018-20783</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-20783.html</URL>
        <Description>CVE-2018-20783</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126713</URL>
        <Description>SUSE Bug 1126713</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1127122</URL>
        <Description>SUSE Bug 1127122</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11034</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11034.html</URL>
        <Description>CVE-2019-11034</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1132838</URL>
        <Description>SUSE Bug 1132838</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11035</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11035.html</URL>
        <Description>CVE-2019-11035</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1132837</URL>
        <Description>SUSE Bug 1132837</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11036</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11036.html</URL>
        <Description>CVE-2019-11036</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1134322</URL>
        <Description>SUSE Bug 1134322</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.</Note>
    </Notes>
    <CVE>CVE-2019-9020</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9020.html</URL>
        <Description>CVE-2019-9020</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126711</URL>
        <Description>SUSE Bug 1126711</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783. This is related to phar_detect_phar_fname_ext in ext/phar/phar.c.</Note>
    </Notes>
    <CVE>CVE-2019-9021</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9021.html</URL>
        <Description>CVE-2019-9021</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126713</URL>
        <Description>SUSE Bug 1126713</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries.</Note>
    </Notes>
    <CVE>CVE-2019-9022</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9022.html</URL>
        <Description>CVE-2019-9022</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126827</URL>
        <Description>SUSE Bug 1126827</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data. These occur in ext/mbstring/oniguruma/regcomp.c, ext/mbstring/oniguruma/regexec.c, ext/mbstring/oniguruma/regparse.c, ext/mbstring/oniguruma/enc/unicode.c, and ext/mbstring/oniguruma/src/utf32_be.c when a multibyte regular expression pattern contains invalid multibyte sequences.</Note>
    </Notes>
    <CVE>CVE-2019-9023</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9023.html</URL>
        <Description>CVE-2019-9023</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126823</URL>
        <Description>SUSE Bug 1126823</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c.</Note>
    </Notes>
    <CVE>CVE-2019-9024</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9024.html</URL>
        <Description>CVE-2019-9024</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126821</URL>
        <Description>SUSE Bug 1126821</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.</Note>
    </Notes>
    <CVE>CVE-2019-9637</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9637.html</URL>
        <Description>CVE-2019-9637</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128892</URL>
        <Description>SUSE Bug 1128892</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the maker_note-&gt;offset relationship to value_len.</Note>
    </Notes>
    <CVE>CVE-2019-9638</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9638.html</URL>
        <Description>CVE-2019-9638</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128889</URL>
        <Description>SUSE Bug 1128889</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.</Note>
    </Notes>
    <CVE>CVE-2019-9639</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9639.html</URL>
        <Description>CVE-2019-9639</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128887</URL>
        <Description>SUSE Bug 1128887</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_process_SOFn.</Note>
    </Notes>
    <CVE>CVE-2019-9640</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9640.html</URL>
        <Description>CVE-2019-9640</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128883</URL>
        <Description>SUSE Bug 1128883</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.</Note>
    </Notes>
    <CVE>CVE-2019-9641</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9641.html</URL>
        <Description>CVE-2019-9641</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128722</URL>
        <Description>SUSE Bug 1128722</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** DISPUTED ** An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a symlink, which currently cannot happen: "This issue allows theoretical compromise of security, but a practical attack is usually impossible."</Note>
    </Notes>
    <CVE>CVE-2019-9675</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.0:apache2-mod_php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bcmath-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-bz2-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-calendar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ctype-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-curl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dba-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-devel-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-dom-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-embed-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-enchant-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-exif-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fastcgi-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fileinfo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-firebird-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-fpm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ftp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gd-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gettext-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-gmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-iconv-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-intl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-json-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-ldap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mbstring-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-mysql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-odbc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-opcache-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-openssl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pcntl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pdo-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pear-Archive_Tar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-pgsql-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-phar-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-posix-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-readline-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-shmop-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-snmp-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-soap-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sockets-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sodium-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sqlite-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvmsg-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvsem-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-sysvshm-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-testresults-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tidy-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-tokenizer-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-wddx-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlreader-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlrpc-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xmlwriter-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-xsl-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zip-7.2.5-lp150.2.19.1</ProductID>
        <ProductID>openSUSE Leap 15.0:php7-zlib-7.2.5-lp150.2.19.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9675.html</URL>
        <Description>CVE-2019-9675</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128886</URL>
        <Description>SUSE Bug 1128886</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
