LWN.net Logo

rPath alert rPSA-2006-0182-1 (php)

From:  rPath Update Announcements <announce-noreply@rpath.com>
To:  security-announce@lists.rpath.com, update-announce@lists.rpath.com
Subject:  rPSA-2006-0182-1 php php-mysql php-pgsql
Date:  Thu, 05 Oct 2006 17:45:48 -0400
Cc:  full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com, lwn@lwn.net

rPath Security Advisory: 2006-0182-1 Published: 2006-10-05 Products: rPath Linux 1 Rating: Major Exposure Level Classification: Remote System User Deterministic Unauthorized Access Updated Versions: php=/conary.rpath.com@rpl:devel//1/4.3.11-15.7-1 php-mysql=/conary.rpath.com@rpl:devel//1/4.3.11-15.7-1 php-pgsql=/conary.rpath.com@rpl:devel//1/4.3.11-15.7-1 References: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... https://issues.rpath.com/browse/RPL-683 Description: Previous versions of the php package contain multiple vulnerabilities, or weaknesses that may enable vulnerabilities in applications written in php. The most severe of these vulnerabilities may enable remote unauthorized access vulnerabilities, depending on the application or applications involved. Other vulnerabilities or weaknesses involve SQL injection attacks, cross-site scripting (XSS), information exposure, and denial of service vulnerabilities.


(Log in to post comments)

Copyright © 2009, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds