Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian: DSA-2195-1 Critical: PHP 5 Race Condition File Removal

debian
Calendar Grey March 19, 2011
Debian Logo
A critical PHP 5 security alert has been released, revealing a race condition vulnerability that may allow unauthorized file deletion on Debian systems. Upgrade now!
Stephane Chazelas discovered that the cronjob of the PHP 5 package in Debian suffers from a race condition which might be used to remove arbitrary files from a system (CVE-2011-044...

Summary

Stephane Chazelas discovered that the cronjob of the PHP 5 package in
Debian suffers from a race condition which might be used to remove
arbitrary files from a system (CVE-2011-0441).

When upgrading your php5-common package take special care to _accept_
the changes to the /etc/cron.d/php5 file. Ignoring them would leave the
system vulnerable.

For the oldstable distribution (lenny), this problem has been fixed in
version 5.2.6.dfsg.1-1+lenny10.

For the stable distribution (squeeze), this problem has been fixed in
version 5.3.3-7+squeeze1.

For the unstable distribution (sid), this problem has been fixed in
version 5.3.6-1.

Additionally, the following vulnerabilities have also been fixed in the
oldstable distribution (lenny):

CVE-2010-3709

Maksymilian Arciemowicz discovered that the ZipArchive class
may dereference a NULL pointer when extracting comments from a zip
archive, leading to application crash and possible denial of
service.

CVE-2010-3710

Stefan Neufeind discovered that the FI...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: php5
CVE ID: CVE-2011-0441 CVE-2010-3709 CVE-2010-3710 CVE-2010-3870

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here