PHP Multiple Local And Remote Vulnerabilities

Solution:
Conectiva has released an advisory (CLSA-2005:955) and fixes to address these and other issues. Please see the referenced advisory for further information regarding obtaining and applying appropriate updates.

Turbolinux has released advisory TLSA-2005-50 along with fixes dealing with this and other issues. Please see the referenced advisory for more information.

Conectiva has released advisory CLA-2005:915 along with fixes dealing with these and other issues. Please see the referenced advisory for more information.

Turbolinux has released advisory TLSA-2005-01-13 along with fixes dealing with this and other issues. Please see the referenced advisory for more information.

Ubuntu Linux has released advisory USN-40-1 along with fixes to address the issue referenced by the CVE candidate CAN-2004-1019 and other issues. Please see the referenced advisory for further information.

OpenPKG has released advisory OpenPKG-SA-2004.053 to address these, and other issues. Please see the referenced advisory for further information.

Mandrake has released advisory MDKSA-2004:151 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.

Gentoo has released updates to address this issue. Updates may be applied by running the following commands as the superuser:

(for PHP)
emerge --sync
emerge --ask --oneshot --verbose ">=dev-php/php-4.3.10"

(for mod_php)
emerge --sync
emerge --ask --oneshot --verbose ">=dev-php/mod_php-4.3.10"

(for php_cgi)
emerge --sync
emerge --ask --oneshot --verbose ">=dev-php/php-cgi-4.3.10"

The vendor has released updated to address these issues:

Trustix Secure Linux has released an advisory (TSLSA-2004-0066) along with fixes dealing with this issue. Please see the referenced advisory for more information.

Red Hat has released Red Hat Enterprise Linux advisory RHSA-2004:687-05 to address various issues in PHP. Please see the advisory in Web references for more information.

Fedora has released advisories FEDORA-2004-567 and FEDORA-2004-568 to address various PHP issues in Fedora Core 2 and Fedora Core 3. Please see the referenced advisories for more information.

Conectiva has released an advisory (CLSA-2005:915) to address issues in PHP. Please see the advisory in Web references for more information.

SGI has released advisory 20050101-01-U to address various issues in SGI Advanced Linux Environment 3. This advisory includes updated SGI ProPack 3 Service Pack 3 packages. Please see the referenced advisory for more information.

S.u.S.E. Linux has made an advisory (SUSE-SA:2005:002) available dealing with this issue. Please see the referenced advisory for more information.

Apple Computers has released advisory APPLE-SA-2005-01-25 along with a security update dealing with this and other issues. Please see the referenced advisory for more information.

Apple Computers has released Mac OS X version 10.3.8 dealing with this issue. This upgrade includes the security patches shipped with the referenced security update.

Fedora has released Fedora Legacy advisory FLSA:2344 to address various issues in Red Hat Linux 7.3, Red Hat Linux 9.0 and Fedora Core 1 for the i386 architecture. Please see the referenced advisory for more information.

Ubuntu Linux has released an advisory USN-99-1 along with fixes dealing with the issues defined by CVE candidates CAN-2004-1018, CAN-2004-1063, and CAN-2004-1064. Please see the referenced advisory for more information.

Ubuntu has released advisory USN-99-2 dealing with issues that arose from the fixes provided with their previous advisory (USN-99-1). Apparently the previous fixes did fix the vulnerabilities, however they broke a substantial amount of PHP functionality. Please see the referenced advisory for more information.

Mandriva has released advisory MDKSA-2005:072 to address these issues. Please see the attached advisory for details on obtaining and applying fixes.

HP has released advisory HPSBMA01212 to address various issue affecting System Management Homepage. Please see the referenced advisory for more information.

HP has released revision 1 of advisory HPSBMA01212 to address various issue affecting System Management Homepage. Please see the referenced advisory for more information.

Revised HP advisory HPSBMA01212 (SSRT5998 Rev.2 HP System Management Homepage(v2.0.x) Denial of Service (DoS) and XSS) including updated resolutions is available. Please see the referenced advisory for more information.

Red Hat has released advisory RHSA-2005:816-10 to address this issue for Red Hat Stronghold for Enterprise Linux. Please see the referenced advisory for further information on obtaining fixes.


Apple Mac OS X 10.2.8

Apple Mac OS X Server 10.2.8

Apple Mac OS X Server 10.3.7

Apple Mac OS X 10.3.7

SGI ProPack 3.0

PHP PHP 4.0 0

PHP PHP 4.0.1

PHP PHP 4.0.1 pl2

PHP PHP 4.0.2

PHP PHP 4.0.3 pl1

PHP PHP 4.0.3

PHP PHP 4.0.5

PHP PHP 4.0.7 RC1

PHP PHP 4.0.7 RC2

PHP PHP 4.0.7

PHP PHP 4.1 .0

PHP PHP 4.2 -dev

PHP PHP 4.2.1

PHP PHP 4.3

PHP PHP 4.3.2

PHP PHP 4.3.3

PHP PHP 4.3.5

PHP PHP 4.3.6

PHP PHP 4.3.8

PHP PHP 4.3.9

PHP PHP 5.0 .0

PHP PHP 5.0 candidate 1

PHP PHP 5.0.1

PHP PHP 5.0.2


 

Privacy Statement
Copyright 2010, SecurityFocus