Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Debian Wheezy DSA-3074-1 Critical: PHP Denial of Service Threat

debian
Calendar Grey November 18, 2014
Debian Logo
Important PHP security update for Debian Wheezy resolves ELF file header vulnerabilities to mitigate potential outages. Upgrade immediately.
Francisco Alonso of Red Hat Product Security found an issue in the file utility, whose code is embedded in PHP, a general-purpose scripting language

Summary

Francisco Alonso of Red Hat Product Security found an issue in the file
utility, whose code is embedded in PHP, a general-purpose scripting
language. When checking ELF files, note headers are incorrectly
checked, thus potentially allowing attackers to cause a denial of
service (out-of-bounds read and application crash) by supplying a
specially crafted ELF file.

As announced in DSA-3064-1 it has been decided to follow the stable
5.4.x releases for the Wheezy php5 packages. Consequently the
vulnerability is addressed by upgrading PHP to a new upstream version
5.4.35, which includes additional bug fixes, new features and possibly
incompatible changes. Please refer to the upstream changelog for more
information:

https://www.php.net/ChangeLog-5.php

For the stable distribution (wheezy), this problem has been fixed in
version 5.4.35-0+deb7u1.

We recommend that you upgrade your php5 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently ask...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: php5
CVE ID: CVE-2014-3710

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here