Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian DSA-1444-1 Critical: PHP5 Remote Session Cookie Flaws

debian
Calendar Grey January 3, 2008
Debian Logo
Enhance your Debian security by upgrading PHP5 packages to mitigate session cookies vulnerabilities and denial of service errors with these steps
Several remote vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language

Summary


It was discovered that the session_start() function allowed the
insertion of attributes into the session cookie.

CVE-2007-3998

Mattias Bengtsson and Philip Olausson discovered that a
programming error in the implementation of the wordwrap() function
allowed denial of service through an infinite loop.

CVE-2007-4658

Stanislav Malyshev discovered that a format string vulnerability
in the money_format() function could allow the execution of
arbitrary code.

CVE-2007-4659

Stefan Esser discovered that execution control flow inside the
zend_alter_ini_entry() function in handled incorrectly in case
of a memory limit violation.

CVE-2007-4660

Gerhard Wagner discovered an integer overflow inside the
chunk_split function().

CVE-2007-5898

Rasmus Lerdorf discovered that incorrect parsing of multibyte
sequences may lead to disclosure of memory contents.

CVE-2007-5899

It was discovered that the output_add_rewrite_var() func...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here