Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: DSA-2408-1 Critical: PHP5 DoS Risks and Update Instructions

debian
Calendar Grey February 13, 2012
Debian Logo
This announcement highlights significant vulnerabilities in PHP5 impacting Debian systems and proposes necessary patches.
Several vulnerabilities have been discovered in PHP, the web scripting language

Summary

Several vulnerabilities have been discovered in PHP, the web scripting
language. The Common Vulnerabilities and Exposures project identifies
the following issues:

CVE-2011-1072

It was discoverd that insecure handling of temporary files in the PEAR
installer could lead to denial of service.

CVE-2011-4153

Maksymilian Arciemowicz discovered that a NULL pointer dereference in
the zend_strndup() function could lead to denial of service.

CVE-2012-0781

Maksymilian Arciemowicz discovered that a NULL pointer dereference in
the tidy_diagnose() function could lead to denial of service.

CVE-2012-0788

It was discovered that missing checks in the handling of PDORow
objects could lead to denial of service.

CVE-2012-0831

It was discovered that the magic_quotes_gpc setting could be disabled
remotely

This update also addresses PHP bugs, which are not treated as security issues
in Debian (see README.Debian.security), but which were fixed nonetheless:
CVE-2010-4697, CVE-2011-1092, CVE-2011-...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: php5
CVE ID: CVE-2011-1072 CVE-2011-4153 CVE-2012-0781 CVE-2012-0788

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here