Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Netflix outside the USA - in Linux & with Tunlr
· Enhanced Mitigation Experience Toolkit 4.0
· Intel Haswell HD Graphics 4600 vs. AMD Radeon Graphics On Linux
· DSA 2709-1: wireshark security update
· Simulator Provides Early Look at iOS 7 on the iPad
· AMD A10-6800K Cracks 8.00 GHz Mark and more
· Ubuntu 13.10 Release Schedule
· PHP 5.5.0 RC3 for Debian 7.0 Wheezy
· Windows 8.1 screenshots leaked, redesigns showcased
· DSA 2708-1: fail2ban security update

Upcoming News
· The SSD Review has Posted a New Article!
· News: AMD's A10-6800K and A10-6700 'Richland' APUs reviewed
· AllPuter.com product launch: 20X Super Long Range Telescope for Galaxy Note 2 Photography
· Intel DZ87KLT-75K "Kinsley Thunderbolt" Motherboard Review @ HiTech Legion
· Corsair Carbide Air 540 ATX Cube Chassis Review
· REVIEW: Diamond Radeon HD 7790 @ PureOverclock
· SanDisk Extreme II 240 GB SSD Review @ OCC
· Ubuntu Weekly Newsletter Issue 321
· Boxes 3.9.3
· [security-announce] SUSE-SU-2013:1022-2: important: Security update for Linux kernel

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· Building a new PC: how EXACTLY to install USB mouse?
by: joyask43
on: 2013-06-09 14:36
6 replies, 2588 views

· Packet CD
by: natalieksh5
on: 2013-06-06 14:19
4 replies, 3420 views

· THE SIMS 2 DIRECTX 9.0C ERROR MESSAGE!! HELP! URGENT!!
by: tandrask34
on: 2013-06-05 14:06
28 replies, 93150 views

· Hello
by: barryherne
on: 2013-06-05 13:09
0 replies, 167 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6883 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » April 2007 » [Security Announce] [ MDKSA-2007:090 ] - Updated php packages fix multiple vulnerabilities

[Security Announce] [ MDKSA-2007:090 ] - Updated php packages fix multiple vulnerabilities

Posted by Bob on: 04/19/2007 07:20 AM [ Print | 0 comment(s) ]

The Mandriva Security Team published a new security update for Mandriva Linux. Here the announcement:




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2007:090
http://www.mandriva.com/security/
_______________________________________________________________________

Package : php
Date : April 18, 2007
Affected: 2007.1
_______________________________________________________________________

Problem Description:

A heap-based buffer overflow vulnerability was found in PHP's gd
extension. A script that could be forced to process WBMP images
from an untrusted source could result in arbitrary code execution
(CVE-2007-1001).

A DoS flaw was found in how PHP processed a deeply nested array.
A remote attacker could cause the PHP intrerpreter to creash
by submitting an input variable with a deeply nested array
(CVE-2007-1285).

The internal filter module in PHP in certain instances did not properly
strip HTML tags, which allowed a remote attacker conduct cross-site
scripting (XSS) attacks (CVE-2007-1454).

A vulnerability in the way the mbstring extension set global variables
was discovered where a script using the mb_parse_str() function to
set global variables could be forced to to enable the register_globals
configuration option, possibly resulting in global variable injection
(CVE-2007-1583).

A vulnerability in how PHP's mail() function processed header data was
discovered. If a script sent mail using a subject header containing
a string from an untrusted source, a remote attacker could send bulk
email to unintended recipients (CVE-2007-1718).

Updated packages have been patched to correct these issues. Also note
that the default use of Suhosin helped to protect against some of
these issues prior to patching.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1001
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1285
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1454
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1583
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1718
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2007.1:
a2a2d7b7103fdaefa792d445d22a65c3 2007.1/i586/libphp5_common5-5.2.1-4.1mdv2007.1.i586.rpm
9aeac43a52784427a4feb19e1d266b50 2007.1/i586/php-cgi-5.2.1-4.1mdv2007.1.i586.rpm
2b5d544dffdb4aa89d74109898205555 2007.1/i586/php-cli-5.2.1-4.1mdv2007.1.i586.rpm
e57b07915a9f7baa656ca9f1eb7ddf1a 2007.1/i586/php-devel-5.2.1-4.1mdv2007.1.i586.rpm
820500b3ffddc56ccbd59518a96f160a 2007.1/i586/php-fcgi-5.2.1-4.1mdv2007.1.i586.rpm
4bf3300a9e01fa6a3c0c8ebb983f5046 2007.1/i586/php-filter-5.2.1-0.1mdv2007.1.i586.rpm
e7765fa71f78bd86f7f12785c0f9cfd9 2007.1/i586/php-gd-5.2.1-1.1mdv2007.1.i586.rpm
49798b443ac0053b48efa66685ecfc44 2007.1/i586/php-mbstring-5.2.1-1.1mdv2007.1.i586.rpm
29f23607a64ba27a0038410a369fc5c0 2007.1/i586/php-openssl-5.2.1-4.1mdv2007.1.i586.rpm
408130c6dac0f507a0b4068174a839d4 2007.1/i586/php-zlib-5.2.1-4.1mdv2007.1.i586.rpm
e3ac02eafad5c201bee1099689d18255 2007.1/SRPMS/php-5.2.1-4.1mdv2007.1.src.rpm
99b6a369a952a88ee5ecb45685777fc6 2007.1/SRPMS/php-filter-5.2.1-0.1mdv2007.1.src.rpm
87967aa8a608f6f832dc070bd8842237 2007.1/SRPMS/php-gd-5.2.1-1.1mdv2007.1.src.rpm
c8f6ec004c7e19e0afe0eaf332b756ad 2007.1/SRPMS/php-mbstring-5.2.1-1.1mdv2007.1.src.rpm

Mandriva Linux 2007.1/X86_64:
75e3b41a9434c1603912e5a7ac4e729f 2007.1/x86_64/lib64php5_common5-5.2.1-4.1mdv2007.1.x86_64.rpm
eb7fc029538ffda1cb559727bf9f28a6 2007.1/x86_64/php-cgi-5.2.1-4.1mdv2007.1.x86_64.rpm
f2a9eae5208089fbb947269a059ef635 2007.1/x86_64/php-cli-5.2.1-4.1mdv2007.1.x86_64.rpm
e8b51aded5740f8d77ebee58e13233c5 2007.1/x86_64/php-devel-5.2.1-4.1mdv2007.1.x86_64.rpm
df8bdb532d4e7ac8a9e9a7a14293a603 2007.1/x86_64/php-fcgi-5.2.1-4.1mdv2007.1.x86_64.rpm
ebef91bd51938b885377d8df7ebb34d0 2007.1/x86_64/php-filter-5.2.1-0.1mdv2007.1.x86_64.rpm
c0d265c231fdeadc7800c95fa27b0fe2 2007.1/x86_64/php-gd-5.2.1-1.1mdv2007.1.x86_64.rpm
4e8fc08c860aef6e5cb1dc786a19025a 2007.1/x86_64/php-mbstring-5.2.1-1.1mdv2007.1.x86_64.rpm
5e2642693f86c41afa9123e7be9592c1 2007.1/x86_64/php-openssl-5.2.1-4.1mdv2007.1.x86_64.rpm
e1117e3ab380560cb1135799573d3fad 2007.1/x86_64/php-zlib-5.2.1-4.1mdv2007.1.x86_64.rpm
e3ac02eafad5c201bee1099689d18255 2007.1/SRPMS/php-5.2.1-4.1mdv2007.1.src.rpm
99b6a369a952a88ee5ecb45685777fc6 2007.1/SRPMS/php-filter-5.2.1-0.1mdv2007.1.src.rpm
87967aa8a608f6f832dc070bd8842237 2007.1/SRPMS/php-gd-5.2.1-1.1mdv2007.1.src.rpm
c8f6ec004c7e19e0afe0eaf332b756ad 2007.1/SRPMS/php-mbstring-5.2.1-1.1mdv2007.1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
lt;security*mandriva.comgt;
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iD8DBQFGJtwnmqjQ0CJFipgRAhMsAKCORTCS969CbEP1bMiIUpPqkIXHCACdFGAd
ngX17q5SRWoiQyfNvJEhBnw=
=4qw+
-----END PGP SIGNATURE-----


Bookmark and Share

« [Security Announce] [ MDKSA-2007:087 ] - Updated php packages fix multiple vulnerabilities · [Security Announce] [ MDKSA-2007:089 ] - Updated php packages fix multiple vulnerabilities »

Linux Compatible » News » April 2007 » [Security Announce] [ MDKSA-2007:090 ] - Updated php packages fix multiple vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition