Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Gentoo 200311-06 Normal: phpSysInfo Directory Traversal Threat

gentoo
Calendar Grey November 24, 2003
Dist Gentoo Esm H88
The phpSysInfo tool has known vulnerabilities that allow unauthorized access to files and execution of potentially harmful code. Users of Gentoo are urged to upgrade promptly.
phpSysInfo contains two vulnerabilities which could allow local files to beread or arbitrary PHP code to be executed, under the privileges of the webserver process.

Summary


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - --------------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200311-06 - - ---------------------------------------------------------------------------
GLSA: 200311-06 package: dev-php/phpsysinfo summary: phpSysInfo directory traversal severity: normal Gentoo bug: 26782 date: 2003-11-22 CVE: CAN-2003-0536 exploit: local affected: <=2.1 fixed:>=2.1-r1
DESCRIPTION:

phpSysInfo contains two vulnerabilities which could allow local files to be read or arbitrary PHP code to be executed, under the privileges of the web server process.

SOLUTION:

It is recommended that all Gentoo Linux users who are running dev-php/phpsysinfo upgrade to the fixed version:
emerge sync emerge '>=dev-php/phpsysinfo-2.1-r1' emerge clean

...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
medium
Lowest
Low
Medium
High
Critical


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3655037_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here