Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Slackware 10.2 Critical Advisory: PHP Package Security Fix

slackware
Calendar Grey August 18, 2006
Dist Slackware Esm H88
Announcement: Recent php updates available for Slackware 10.2 addressing significant security vulnerabilities and enhancing package functionality.
New php packages are available for Slackware 10.2 and -current to fix security and other issues

Summary

Here are the details from the Slackware 10.2 ChangeLog: patches/packages/php-4.4.4-i486-1_slack10.2.tgz: Upgraded to php-4.4.4. Some of the security issues fixed in this release include: * Added missing safe_mode/open_basedir checks inside the error_log(), file_exists(), imap_open() and imap_reopen() functions. * Fixed possible open_basedir/safe_mode bypass in cURL extension. * Fixed a buffer overflow inside sscanf() function. (* Security fix *) testing/packages/php-5.1.5/php-5.1.5-i486-1_slack10.2.tgz: Usually packages in /testing aren't patched or upgraded after a release, but since quite a few people have probably deployed this one, and it is a network service, an upgraded package is being provided. Upgraded to php-5.1.5. Some of the security issues fixed in this release include: * Added missing safe_mode/open_basedir checks inside the error_log(), file_exists(), imap_open() and imap_reopen() functions. * Fixed possible

Read the Full Advisory

Where Find New Packages

Updated packages for Slackware 10.2:
Updated packages for Slackware -current:

MD5 Signatures

Slackware 10.2 packages: c7e6c918828be69380a0b6cc86a311be php-4.4.4-i486-1_slack10.2.tgz c8895a309e785de5234ece30600a6617 php-5.1.5-i486-1_slack10.2.tgz
Slackware -current packages: cd87305b9576669ecb58df181acf316c php-4.4.4-i486-1.tgz 1b15cbd166f2be08c1adaad6a19409b9 php-5.1.5-i486-1.tgz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg php-4.4.4-i486-1_slack10.2.tgz

Related News

Your message here