LWN.net Logo

php5: multiple vulnerabilities

Package(s):php5 CVE #(s):CVE-2008-5557 CVE-2008-5624 CVE-2008-5658 CVE-2007-5625
Created:February 13, 2009 Updated:February 23, 2010
Description: From the Ubuntu advisory:

It was discovered that PHP did not properly handle Unicode conversion in the mbstring extension. If a PHP application were tricked into processing a specially crafted string containing an HTML entity, an attacker could execute arbitrary code with application privileges. (CVE-2008-5557)

It was discovered that PHP did not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function. An attacker could exploit this issue to bypass safe_mode restrictions. (CVE-2008-5624)

It was discovered that PHP did not properly enforce error_log safe_mode restrictions when set by php_admin_flag in the Apache configuration file. A local attacker could create a specially crafted PHP script that would overwrite arbitrary files. (CVE-2007-5625)

It was discovered that PHP contained a flaw in the ZipArchive::extractTo function. If a PHP application were tricked into processing a specially crafted zip file that had filenames containing "..", an attacker could write arbitrary files within the filesystem. This issue only applied to Ubuntu 7.10, 8.04 LTS, and 8.10. (CVE-2008-5658)

Alerts:
Gentoo 201001-03 2010-01-05
SuSE SUSE-SR:2010:005 2010-02-23
Debian DSA-1940-1 2009-11-25
Fedora FEDORA-2009-3768 2009-04-21
Fedora FEDORA-2009-3848 2009-04-21
Debian DSA-1789-1 2009-05-04
Red Hat RHSA-2009:0350-01 2009-04-14
CentOS CESA-2009:0338 2009-04-07
CentOS CESA-2009:0337 2009-04-06
Red Hat RHSA-2009:0337-01 2009-04-06
Red Hat RHSA-2009:0338-01 2009-04-06
Mandriva MDVSA-2009:065 2009-03-05
rPath rPSA-2009-0035-1 2009-03-02
Mandriva MDVSA-2009:045 2009-02-20
SuSE SUSE-SR:2009:004 2009-02-17
Ubuntu USN-720-1 2009-02-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds