Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Slackware 11.0: 2007-314-02 Critical: PHP Zero-Length Issue Fix

slackware
Calendar Grey November 11, 2007
Dist Slackware Esm H88
Important security patch released for Slackware 11.0 addressing zero-byte /usr/bin/php-cgi vulnerability. Upgrade immediately!
The security/bug fix update for Slackware 11.0 has been reissued to fix a zero-length /usr/bin/php-cgi

Summary

Here are the details from the Slackware 11.0 ChangeLog: extra/php5/php-5.2.5-i486-2_slack11.0.tgz: The security/bug fix update for Slackware 11.0 has been reissued to fix a zero-length /usr/bin/php-cgi. Thanks to TJ Munro for pointing this out. We appreciate the fast weekend Q/A. :-) This package should be installed rather than the previously released php-5.2.5-i486-1_slack11.0 (unless you do not use /usr/php/php-cgi in which case either package will do.) (* Security fix *) Where to find the new package: HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror

Read the Full Advisory

Where Find New Packages

MD5 Signatures

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: First, stop Apache: # apachectl stop Next, upgrade to the new PHP package: # upgradepkg php-5.2.5-i486-2_slack11.0.tgz Finally, restart Apache: # apachectl start Or, for Apache using SSL: # apachectl startssl

Related News

Your message here