LWN.net Logo

Pardus alert 2011-35 (mod_php php-cli php-common)

From:  Meltem <meltem@pardus.org.tr>
To:  pardus-security@pardus.org.tr
Subject:  [Pardus-security] [PLSA 2011-35] PHP: Multiple vulnerabilities
Date:  Sat, 12 Feb 2011 10:25:22 +0200
Message-ID:  <201102121025.22717.meltem@pardus.org.tr>
Archive-link:  Article, Thread

------------------------------------------------------------------------ Pardus Linux Security Advisory 2011-35 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2011-02-12 Severity: 3 Type: Local ------------------------------------------------------------------------ Summary ======= Multiple vulnerabilities have been fixed in php. Description =========== CVE-2011-0752: The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input. CVE-2011-0753: Race condition in the PCNTL extension in PHP before 5.3.4, when a user-defined signal handler exists, might allow context-dependent attackers to cause a denial of service (memory corruption) via a large number of concurrent signals. CVE-2011-0755: Integer overflow in the mt_rand function in PHP before 5.3.4 might make it easier for context-dependent attackers to predict the return values by leveraging a script's use of a large max parameter, as demonstrated by a value that exceeds mt_getrandmax. Affected packages: Pardus 2009: mod_php, all before 5.2.14-86-20 php-cli, all before 5.2.14-86-20 php-common, all before 5.2.14-86-20 Resolution ========== There are update(s) for mod_php, php-cli, php-common. You can update them via Package Manager or with a single command from console: pisi up mod_php php-cli php-common References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=16720 * http://bugs.pardus.org.tr/show_bug.cgi?id=16770 * http://bugs.pardus.org.tr/show_bug.cgi?id=16774 ------------------------------------------------------------------------ _______________________________________________ Pardus-Security mailing list Pardus-Security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds