Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian Wheezy: DSA-3008-2 Moderate: PHP5 Sessionclean Error Correction

debian
Calendar Grey August 21, 2014
Debian Logo
Debian patches resolve nodejs versioning flaw highlighted in DSA-3009-1, addressing key vulnerabilities recognized for reliability.
This update corrects a packaging error for the packages released in DSA-3008-1

Summary

Several vulnerabilities were found in PHP, a general-purpose scripting
language commonly used for web application development. The Common
Vulnerabilities and Exposures project identifies the following problems:

CVE-2014-3538

It was discovered that the original fix for CVE-2013-7345 did not
sufficiently address the problem. A remote attacker could still
cause a denial of service (CPU consumption) via a specially-crafted
input file that triggers backtracking during processing of an awk
regular expression rule.

CVE-2014-3587

It was discovered that the CDF parser of the fileinfo module does
not properly process malformed files in the Composite Document File
(CDF) format, leading to crashes.

CVE-2014-3597

It was discovered that the original fix for CVE-2014-4049 did not
completely address the issue. A malicious server or
man-in-the-middle attacker could cause a denial of service (crash)
and possibly execute arbitrary code via a crafted DNS TXT record.

CVE-20...

Read the Full Advisory

Package: php5
CVE ID: CVE-2014-3538 CVE-2014-3587 CVE-2014-3597 CVE-2014-4670

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here