LWN.net Logo

Critical PHP vulnerability being fixed (The H)

Critical PHP vulnerability being fixed (The H)

Posted Feb 3, 2012 2:43 UTC (Fri) by fimbulvetr (subscriber, #41019)
In reply to: Critical PHP vulnerability being fixed (The H) by drag
Parent article: Critical PHP vulnerability being fixed (The H)

Well, to be fair, a number of distros did backport the fix without noticing the vulnerability.

Remote execution aside, sudo did just suffer a comparable issue where new code had been added but not fully vetted. The only real difference to is that I'd expect more from the sudo authors.

Ubuntu, FWIW, doesn't appear to have fixed the original 5.3.9 bug and thus those users may suffer the 5.3.9 DOSing, but hypothetically no remote execution:
https://bugs.launchpad.net/bugs/cve/2011-4885


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds