Stephane Chazelas discovered that the cronjob of the PHP 5 package in
Debian suffers from a race condition which might be used to remove
arbitrary files from a system (CVE-2011-0441).
When upgrading your php5-common package take special care to _accept_
the changes to the /etc/cron.d/php5 file. Ignoring them would leave the
system vulnerable.
For the oldstable distribution (lenny), this problem has been fixed in
version 5.2.6.dfsg.1-1+lenny10.
For the stable distribution (squeeze), this problem has been fixed in
version 5.3.3-7+squeeze1.
For the unstable distribution (sid), this problem has been fixed in
version 5.3.6-1.
Additionally, the following vulnerabilities have also been fixed in the
oldstable distribution (lenny):
CVE-2010-3709
Maksymilian Arciemowicz discovered that the ZipArchive class
may dereference a NULL pointer when extracting comments from a zip
archive, leading to application crash and possible denial of
service.
CVE-2010-3710
Stefan Neufeind discovered that the FI...
Get the latest Linux and open source security news straight to your inbox.