Package : php5
Vulnerability : several
Problem type : local/remote
Debian-specific: no
CVE Id(s) : CVE-2007-3806 CVE-2008-1384 CVE-2008-2050 CVE-2008-2051
Debian Bug : 479723
Several vulnerabilities have been discovered in PHP, a server-side,
HTML-embedded scripting language. The Common Vulnerabilities and
Exposures project identifies the following problems:
CVE-2007-3806
The glob function allows context-dependent attackers to cause
a denial of service and possibly execute arbitrary code via
an invalid value of the flags parameter.
CVE-2008-1384
Integer overflow allows context-dependent attackers to cause
a denial of service and possibly have other impact via a
printf format parameter with a large width specifier.
CVE-2008-2050
Stack-based buffer overflow in the FastCGI SAPI.
CVE-2008-2051
The escapeshellcmd API function could be attacked via
incomplete multibyte chars.
This update als includes a fix which was pending for the next Debian
4.0 `etch' stable update, for crashes in php5-recode (Debian bug 459020).
For the stable distribution (etch), these problems have been fixed in
version 5.2.0-8+etch11.
For the unstable distribution (sid), these problems have been fixed in
version 5.2.6-1.
We recommend that you upgrade your php5 package.
Upgrade instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update by adding the resources from the
footer to the proper configuration.
Debian GNU/Linux 4.0 alias etch
- -------------------------------
These files will probably be moved into the stable distribution on
its next update.
- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce_at_lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iQEVAwUBSCcL5Wz0hbPcukPfAQKB5gf/c/J4Zpjl/A8revQ9SbsBK1J96Y2Mg/jq
P1i8WGH6UYF3q1uLTtne4JaC5cYl1f7Fa0K4OHzi+0rwNBzqky5ZMk9HvCdEt1+q
OB1iKLf5elwgvt3lrHpHp1Vb6OmgjChtLsCQ5oEtL8++wzyaaKc3UEArX10LPm4M
n8mU2xeXQzsmrJCxbyB3GZMq0ZIEL7+1logLJrPlwutc9ZhQLs4cjSLy8w+MfkHF
KmAkKQaElG/nzv/QXBT2zT2W/CsnMRPBmmDvjJAbuxQdswfUFELO4ryC3N+9M7/G
yr8EQtR/ZoJv2JeFeQ6wbAxmCKzA3+GyFO/FMfZ7qWOrEmcKvFYLdA==
=+vxu
-----END PGP SIGNATURE-----
Received on May 12 2008