Alerts This Week
Warning Icon 1 1,154
Alerts This Week
Warning Icon 1 1,154

Red Hat Enterprise 2.1 RHSA-2007:0081-01 Important: PHP Buffer Overflow

red hat
Calendar Grey February 21, 2007
Dist Redhat Esm H88
Crucial security patch for PHP on Red Hat deals with various vulnerabilities. Necessary to upgrade to reduce potential threats.
Updated PHP packages that fix several security issues are now available for Red Hat Enterprise Linux 2.1

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system.

5. Bug IDs fixed (http://bugzilla.redhat.com/):

229332 - CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)

6. RPMs required:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1:

SRPMS: 3c1babd0b650d968fb05c3fc941e1328 php-4.1.2-2.14.src.rpm

i386: a4e8107d7d04c391924e1a489c4e8b1f php-4.1.2-2.14.i386.rpm 3eb84ba09f48aafdd82fd273847c0ab7 php-devel-4.1.2-2.14.i386.rpm 547ee3ef9a42650b7968ca5d847cb362 php-imap-4.1.2-2.14.i386.rpm 27ad3782dd0bd6c398f6759c615a7a8e php-ldap-4.1.2-2.14.i386.rpm 8f5cb33e88ebc83c80fd69608daa943b php-manual-4.1.2-2.14.i386.rpm 13f14591befae51d6c2072e29190510e php-mysql-4.1.2-2.14.i386.rpm 3c5a5d6027e2f960091044d63205e00b php-odbc-4.1.2-2.14.i386.rpm b14c7e1d15965c39febb475897ec9602 php-pgsql-4.1.2-2.14.i386.rpm

ia64: e62f6a7585c07440f283543af205720c php-4.1.2-2.14.ia64.rpm ddb2e7b85468f5c222ba1f09fcfdad9c php-devel-4.1.2-2.14.ia64.rpm b8f556303277dc3847d24acff42d530f php-imap-4.1.2-2.14.ia64.rpm 444ae771d27b6eb5a4b9fc20df23ee46 php-ldap-4.1.2-2.14.ia64.rpm d95de85e804a28dfbf0e1cf2dee9b184 php-manual-4.1.2-2.14.ia64.rpm 5e8f596c3109b090b1de0b40faa3575c php-mysql-4.1.2-2.14.ia64.rpm b017004385456310eaf7108b5e48a1fd php-odbc-4.1.2-2.14.ia64.rpm 2b0984f7324d18f6f605b16ab0e0bcc1 php-pgsql-4.1.2-2.14.ia64.rpm

Red Hat Linux Advanced Workstation 2.1:

SRPMS: 3c1babd0b650d968fb05c3fc941e1328 php-4.1.2-2.14.src.rpm

ia64: e62f6a7585c07440f283543af205720c php-4.1.2-2.14.ia64.rpm ddb2e7b85468f5c222ba1f09fcfdad9c php-devel-4.1.2-2.14.ia64.rpm b8f556303277dc3847d24acff42d530f php-imap-4.1.2-2.14.ia64.rpm 444ae771d27b6eb5a4b9fc20df23ee46 php-ldap-4.1.2-2.14.ia64.rpm d95de85e804a28dfbf0e1cf2dee9b184 php-manual-4.1.2-2.14.ia64.rpm 5e8f596c3109b090b1de0b40faa3575c php-mysql-4.1.2-2.14.ia64.rpm b017004385456310eaf7108b5e48a1fd php-odbc-4.1.2-2.14.ia64.rpm 2b0984f7324d18f6f605b16ab0e0bcc1 php-pgsql-4.1.2-2.14.ia64.rpm

Red Hat Enterprise Linux ES version 2.1:

SRPMS: 3c1babd0b650d968fb05c3fc941e1328 php-4.1.2-2.14.src.rpm

i386: a4e8107d7d04c391924e1a489c4e8b1f php-4.1.2-2.14.i386.rpm 3eb84ba09f48aafdd82fd273847c0ab7 php-devel-4.1.2-2.14.i386.rpm 547ee3ef9a42650b7968ca5d847cb362 php-imap-4.1.2-2.14.i386.rpm 27ad3782dd0bd6c398f6759c615a7a8e php-ldap-4.1.2-2.14.i386.rpm 8f5cb33e88ebc83c80fd69608daa943b php-manual-4.1.2-2.14.i386.rpm 13f14591befae51d6c2072e29190510e php-mysql-4.1.2-2.14.i386.rpm 3c5a5d6027e2f960091044d63205e00b php-odbc-4.1.2-2.14.i386.rpm b14c7e1d15965c39febb475897ec9602 php-pgsql-4.1.2-2.14.i386.rpm

Red Hat Enterprise Linux WS version 2.1:

SRPMS: 3c1babd0b650d968fb05c3fc941e1328 php-4.1.2-2.14.src.rpm

i386: a4e8107d7d04c391924e1a489c4e8b1f php-4.1.2-2.14.i386.rpm 3eb84ba09f48aafdd82fd273847c0ab7 php-devel-4.1.2-2.14.i386.rpm 547ee3ef9a42650b7968ca5d847cb362 php-imap-4.1.2-2.14.i386.rpm 27ad3782dd0bd6c398f6759c615a7a8e php-ldap-4.1.2-2.14.i386.rpm 8f5cb33e88ebc83c80fd69608daa943b php-manual-4.1.2-2.14.i386.rpm 13f14591befae51d6c2072e29190510e php-mysql-4.1.2-2.14.i386.rpm 3c5a5d6027e2f960091044d63205e00b php-odbc-4.1.2-2.14.i386.rpm b14c7e1d15965c39febb475897ec9602 php-pgsql-4.1.2-2.14.i386.rpm

These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package

Summary

References

https://www.cve.org/CVERecord?id=CVE-2007-0906 https://www.cve.org/CVERecord?id=CVE-2007-0907 https://www.cve.org/CVERecord?id=CVE-2007-0908 https://www.cve.org/CVERecord?id=CVE-2007-0909 https://www.cve.org/CVERecord?id=CVE-2007-0910 https://www.cve.org/CVERecord?id=CVE-2007-0988 https://access.redhat.com/security/updates/classification#important

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2007:0081-01
Issue date: 2007-02-21
Updated on: 2007-02-21
Product: Red Hat Enterprise Linux

Topic

Relevant Releases Architectures

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64

Red Hat Linux Advanced Workstation 2.1 - ia64

Red Hat Enterprise Linux ES version 2.1 - i386

Red Hat Enterprise Linux WS version 2.1 - i386

Bugs Fixed

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here