|
|
| |
|
| |
php: multiple vulnerabilities
| Package(s): | php |
CVE #(s): | |
| Created: | August 18, 2006 |
Updated: | August 23, 2006 |
| Description: |
Several vulnerabilities have been fixed in PHP 4.4.4 and 5.1.5.
- Added missing safe_mode/open_basedir checks inside the error_log(),
file_exists(), imap_open() and imap_reopen() functions.
- Fixed overflows inside str_repeat() and wordwrap() functions on 64bit
systems.
- Fixed possible open_basedir/safe_mode bypass in cURL extension and on
PHP 5.1.5 with realpath cache.
- Fixed overflow in GD extension on invalid GIF images.
- Fixed a buffer overflow inside sscanf() function.
- Fixed an out of bounds read inside stripos() function.
- Fixed memory_limit restriction on 64 bit system.
|
| Alerts: |
|
( Log in to post comments)
|
|
|