| From: |
| rPath Update Announcements <announce-noreply@rpath.com> |
| To: |
| security-announce@lists.rpath.com, update-announce@lists.rpath.com |
| Subject: |
| rPSA-2006-0182-1 php php-mysql php-pgsql |
| Date: |
| Thu, 05 Oct 2006 17:45:48 -0400 |
| Cc: |
| full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com, lwn@lwn.net |
rPath Security Advisory: 2006-0182-1
Published: 2006-10-05
Products: rPath Linux 1
Rating: Major
Exposure Level Classification:
Remote System User Deterministic Unauthorized Access
Updated Versions:
php=/conary.rpath.com@rpl:devel//1/4.3.11-15.7-1
php-mysql=/conary.rpath.com@rpl:devel//1/4.3.11-15.7-1
php-pgsql=/conary.rpath.com@rpl:devel//1/4.3.11-15.7-1
References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200...
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200...
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200...
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200...
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200...
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200...
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200...
https://issues.rpath.com/browse/RPL-683
Description:
Previous versions of the php package contain multiple vulnerabilities,
or weaknesses that may enable vulnerabilities in applications written
in php. The most severe of these vulnerabilities may enable remote
unauthorized access vulnerabilities, depending on the application or
applications involved. Other vulnerabilities or weaknesses involve
SQL injection attacks, cross-site scripting (XSS), information
exposure, and denial of service vulnerabilities.
(
Log in to post comments)