Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Debian: DSA-1789-1 Critical: PHP5 Multiple Remote Threats

debian
Calendar Grey May 4, 2009
Debian Logo
Various security issues in PHP 5 outlined in DSA-1789-1 for Debian. It is advised to upgrade to prevent potential remote exploitation.
Several remote vulnerabilities have been discovered in the PHP 5 hypertext preprocessor

Summary

The following four vulnerabilities have already been fixed in the stable
(lenny) version of php5 prior to the release of lenny. This update now
addresses them for etch (oldstable) aswell:

CVE-2008-2107 / CVE-2008-2108

The GENERATE_SEED macro has several problems that make predicting
generated random numbers easier, facilitating attacks against measures
that use rand() or mt_rand() as part of a protection.

CVE-2008-5557

A buffer overflow in the mbstring extension allows attackers to execute
arbitrary code via a crafted string containing an HTML entity.

CVE-2008-5624

The page_uid and page_gid variables are not correctly set, allowing
use of some functionality intended to be restricted to root.

CVE-2008-5658

Directory traversal vulnerability in the ZipArchive::extractTo function
allows attackers to write arbitrary files via a ZIP file with a file
whose name contains .. (dot dot) sequences.

This update also addresses the following three vulnerabilities for both
old...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here