Package : php4
Vulnerability : several
Problem type : local/remote
Debian-specific: no
CVE Id(s) : CVE-2007-3799 CVE-2007-3806 CVE-2007-3998 CVE-2007-4657
CVE-2008-2051
Several vulnerabilities have been discovered in PHP version 4, a
server-side, HTML-embedded scripting language. The Common Vulnerabilities
and Exposures project identifies the following problems:
CVE-2007-3799
The session_start function allows remote attackers to insert
arbitrary attributes into the session cookie via special characters
in a cookie that is obtained from various parameters.
CVE-2007-3806
A denial of service was possible through a malicious script abusing
the glob() function.
CVE-2007-3998
Certain maliciously constructed input to the wordwrap() function could
lead to a denial of service attack.
CVE-2007-4657
Large len values of the stspn() or strcspn() functions could allow an
attacker to trigger integer overflows to expose memory or cause denial
of service.
CVE-2008-2051
The escapeshellcmd API function could be attacked via incomplete
multibyte chars.
For the stable distribution (etch), these problems have been fixed in
version 6:4.4.4-8+etch6.
The php4 are no longer present the unstable distribution (sid).
We recommend that you upgrade your php4 package.
Upgrade instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update by adding the resources from the
footer to the proper configuration.
Debian GNU/Linux 4.0 alias etch
- -------------------------------
These files will probably be moved into the stable distribution on
its next update.
- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce_at_lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iQEVAwUBSC7E02z0hbPcukPfAQLoUwf/So2zkx/Z0AymEd+QeWsOoRoXbiQxWVbt
/vD4ievsQpuIfvDYV4AzRNWdIFINbPWowQVHKVYdcjsKwpKJDcj2A+Af9kXlIexQ
c41Op995Oocv6t3aDrzFpCRggcxU2b4KOp0KNMvE40WHCzV9vD30kgEFDyzwUVfa
x+te4xHIrBs+5s1eDh0u3fqGHdAvg3khWsL3j67yellq9HIfWQ7Hb9QGAir7nJsJ
FIm0K/paQyQLpyE4k/fnOgMBU/P1qo69teZKidKkScPJWodzT4n47eTRDgR/RA9T
M2Fc7rjD+CGo/OtfaLN2EHIl98KnfGBYWK7DoIbBduZRVYAFX8fHSA==
=r5o/
-----END PGP SIGNATURE-----
Received on May 17 2008