-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

______________________________________________________________________________

                        SUSE Security Announcement

        Package:                php4, php5
        Announcement ID:        SUSE-SA:2005:049
        Date:                   Tue, 30 Aug 2005 15:00:00 +0000
        Affected Products:      9.0, 9.1, 9.2, 9.3
                                SUSE Linux Enterprise Server 8, 9
        Vulnerability Type:     remote code execution
        Severity (1-10):        8
        SUSE Default Package:   yes
        Cross-References:       CAN-2005-2498
                                CAN-2005-2491


    Content of This Advisory:
        1) Security Vulnerability Resolved:
             Pear::XML_RPC code injection problem, pcre integer overflow
           Problem Description
        2) Solution or Work-Around
        3) Special Instructions and Notes
        4) Package Location and Checksums
        5) Pending Vulnerabilities, Solutions, and Work-Arounds:
            See SUSE Security Summary Report.
        6) Authenticity Verification and Additional Information

______________________________________________________________________________

1) Problem Description and Brief Discussion

   This update fixes the following security issues in the PHP scripting
   language.

   - Bugs in the PEAR::XML_RPC library allowed remote attackers to pass
     arbitrary PHP code to the eval() function (CAN-2005-1921,
     CAN-2005-2498).

     The Pear::XML_RPC library is not used by default in SUSE Linux, but
     might be used by third-party PHP applications.

   - A integer overflow bug was found in the PCRE (perl compatible regular
     expression) library which could be used by an attacker to potentially
     execute code. (CAN-2005-2491)

2) Solution or Work-Around

   Please install the updated packages.

3) Special Instructions and Notes

   Make sure you restart the web server using PHP after the update.

4) Package Location and Checksums

   The preferred method for installing security updates is to use the YaST
   Online Update (YOU) tool. YOU detects which updates are required and
   automatically performs the necessary steps to verify and install them.
   Alternatively, download the update packages for your distribution manually
   and verify their integrity by the methods listed in Section 6 of this
   announcement. Then install the packages using the command

     rpm -Fhv 

   to apply the update, replacing  with the filename of the
   downloaded RPM package.

   Our maintenance customers are notified individually. The packages are
   offered for installation from the maintenance web.


   x86 Platform:

   SUSE Linux 9.3:
             f4e6d7578b6ae62a0b49989a3be4ef4b
             79bb1fdc66068aba68a253d16a02f471
             08708573a0dee6ea412f7afc0d472244
             ffc0d7f665be377b1c9450f16d8b0b35
             44bbb9ec8f40b92030a591a718312ce1
             081168bede1cc4409c17fe71ea891f6e
             f6beca45181a6f92cba938b6b1009b39
             c35765443f99ee337e8df8b54414ef74
             9681a8e5dd6db224689d8e5dc6f07aff
             9f18c0bce655a1eda2fa9db9cb703e68
             d39bb57b5df06dc64e3cc5cf484c030c
             514561227c94e8af808dfb9d47a8143a
             a08670d24ea2af4e22425b9879804fa9
             9c374d9ed218a85399d5a529f8f97417
             4cba59009162137d5e4a79f0c355ec15
             a31dd5f81ebe25fc69b4a3a29321fed9
             4b1cf3f9ccfc1f4a546f188768a54da2
             4cddafbceded22b220e48542f6371337

   SUSE Linux 9.2:
             b5f30d4fcad5a1f8a3e5dfc9db519914
             eed1a644b3908e719d81359b96ef4244
             3a9fd735f7897fb97be921dee4afe850
             6145bf500d49378b1f7cd5441612ad92
             38c72905c9c47a6ab680faa781927020
             8483c7ce1b73710f03120fb7cf009740
             202af06b5ee93fd667a7484d01c3089b
             498f23a90eab4da6a06de67e44a84014
             254f0ee5ac6d04f244a8cfd171fdff57
             528b00aeb3433f5829cd070a84cfeeb9

   SUSE Linux 9.1:
             214e4ef40cb48c998342995cac9d04b8
             f2d4e625ea55fa7ead3a754238ca7078
             fabfae99a0462b49ec5f1109cd6820a9
             ca1aaef816f44495a90d4fb487a26524
             66fe3a880315e1de5d408a5dcaca3680
             c21383cbc809a455c7eff45b8f533f52
             21363ed91ae437ca66a97ba597c2529c
             ebdd8e83894392f455f57f8bf96022ea
             f6bf0f02c69fe67d2b229000bb5c93de
             a2b8fbb9a6f9720e332d311096280aa8
             7a82acc19b8817a5b80e87bacfab33c7
             654aa331a6353a34937d6688f8cb6d36
             fd388995234e536a8d72983f3eb51ce1
             d47c5fee9862e92daa317f48f3337b28
             29bd1f214d830de2f70c093ad428452b
   source rpm(s):
             dd586cc978292519a290d27439a9da28

   SUSE Linux 9.0:
             72dc636b72a3e8b8703eb3d6b770ca61
             a0934b5d7f27d2d86a9587dd5981e550
             8a9553c2157af21753305fc013bd4b75
             9dce9a4f911cd1deed07096d5c5be00a
             5fab53be54518170d3885459ee51232f
             fd0e4d8d4a938711bc2a93c50a5a1be9
   source rpm(s):
             f9f22aee983bbb30e2a10b4343155587

   x86-64 Platform:

   SUSE Linux 9.3:
             a3566598438cadf224fd5b1a126a6024
             c6186821c83c329729f282fb8ca34be8
             ac65da1e1109543f424e6abb1fa99201
             70c628abfaef3a4749c4683a9fa6de25
             3dde57064fcec2d5fbb5eb8397174f43
             be6b952045156e8e39286cf31567f8c2
             afcaf39f5dd99859f789e68d8183895d
             62d056349b1fffe351fb0d88c3d69905
             1352247dee304526e024d8c4132fc04c
             0b76af3f88a4482fc59b3e7ddba60ebd
             915b53c32abeff07e509c7480946ba40
             99df6f9e22a93b0ae6a07689d04af43e
             e0cdc636f1234231653f0cdc354272be
             6c25772c43098d4ceeba2637a06b21a0
             2621bf4f9a6582135e10e60861c16c73
             7a008af048763a61e05b5d90c94cdaa7
             408072d7b235721984593b2daf4cc56f
   source rpm(s):
             2becfb1be4d621a677305153b6aeb04e
             2ec1cf29732840e136d7291677a58c46

   SUSE Linux 9.2:
             b138dceb7fbc705676fc37c1959a7265
             d8b17ce13cc0ffd38ab340d1374c27e9
             89572dce1437f77010f224dde5f77b84
             af4ef7e10f30648c8d6397b3453eade5
             138673e37f145774abb545ff17b2d873
             0af41c67a8a227f2e59d47530b79aef4
             a267c09190f6782bd408f3b9d451755f
             400df3b11703fba3c363cb6cfd90425f
             a0b37ffe882338dd6ed727fd657f7180
   source rpm(s):
             b987cb8e60e74cac76b83a6b85092a13

   SUSE Linux 9.1:
             1088ec323766692fdf30252386dd17d5
             b32bec6f686d83cdff538c661c9bd693
             6a4a2ee9725a7cbeda50f0bf3c30e1b0
             eaace43d9273a5fbf79fa47af64cb764
             23ea7c1d4f9d4088201a39106062a169
             dd0df0fc61f5331bb7fa8d2fff929cff
             e14efdeda23c06aac65e55db83555328
             1a81b3b1c7b6562c330e5fd8afb33489
             4e5afde23ba37c5c83bcd2f4ea23e5a4
             3ec4a646f4254293af2423b1690e68c3
             70de23feb7e561f4f9225d82dd51ff6f
             de543ba0db1f755f16afa77a1ad6ad06
             973fcbda433eb8187b426ec93e8fefb2
             42c4cc25a00aa42b83aad8be9cbcc265
             5941a332be13d1a602d6bb2e48c7b188
   source rpm(s):
             2e021c18d66c00989a1fe019cb241064

   SUSE Linux 9.0:
             c83318085caf523c2a4afcf7e707aaf4
             f10309b963b542c0dedb3533c139bc9a
             19c7918452fdaee52677f3a7adad2863
             deebef74b38aca7af032deec065a8f5e
             9979f459d175849bd4eda540a8044c3a
             f15b60a9766e6d9fd405a854e71e9809
   source rpm(s):
             5bb5ca24643ef02c1e9b645a2656670c


______________________________________________________________________________

5) Pending Vulnerabilities, Solutions, and Work-Arounds:

   See SUSE Security Summary Report.
______________________________________________________________________________

6) Authenticity Verification and Additional Information

  - Announcement authenticity verification:

    SUSE security announcements are published via mailing lists and on Web
    sites. The authenticity and integrity of a SUSE security announcement is
    guaranteed by a cryptographic signature in each announcement. All SUSE
    security announcements are published with a valid signature.

    To verify the signature of the announcement, save it as text into a file
    and run the command

      gpg --verify 

    replacing  with the name of the file where you saved the
    announcement. The output for a valid signature looks like:

      gpg: Signature made  using RSA key ID 3D25D3D9
      gpg: Good signature from "SuSE Security Team "

    where  is replaced by the date the document was signed.

    If the security team's key is not contained in your key ring, you can
    import it from the first installation CD. To import the key, use the
    command

      gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc

  - Package authenticity verification:

    SUSE update packages are available on many mirror FTP servers all over the
    world. While this service is considered valuable and important to the free
    and open source software community, the authenticity and the integrity of
    a package needs to be verified to ensure that it has not been tampered
    with.

    There are two verification methods that can be used independently from
    each other to prove the authenticity of a downloaded file or RPM package:

    1) Using the internal gpg signatures of the rpm package
    2) MD5 checksums as provided in this announcement

    1) The internal rpm package signatures provide an easy way to verify the
       authenticity of an RPM package. Use the command

        rpm -v --checksig 

       to verify the signature of the package, replacing  with the
       filename of the RPM package downloaded. The package is unmodified if it
       contains a valid signature from build@suse.de with the key ID 9C800ACA.

       This key is automatically imported into the RPM database (on
       RPMv4-based distributions) and the gpg key ring of 'root' during
       installation. You can also find it on the first installation CD and at
       the end of this announcement.

    2) If you need an alternative means of verification, use the md5sum
       command to verify the authenticity of the packages. Execute the command

         md5sum 

       after you downloaded the file from a SUSE FTP server or its mirrors.
       Then compare the resulting md5sum with the one that is listed in the
       SUSE security announcement. Because the announcement containing the
       checksums is cryptographically signed (by security@suse.de), the
       checksums show proof of the authenticity of the package if the
       signature of the announcement is valid. Note that the md5 sums
       published in the SUSE Security Announcements are valid for the
       respective packages only. Newer versions of these packages cannot be
       verified.

  - SUSE runs two security mailing lists to which any interested party may
    subscribe:

    suse-security@suse.com
        -   General Linux and SUSE security discussion.
            All SUSE security announcements are sent to this list.
            To subscribe, send an e-mail to
                .

    suse-security-announce@suse.com
        -   SUSE's announce-only mailing list.
            Only SUSE's security announcements are sent to this list.
            To subscribe, send an e-mail to
                .

    For general information or the frequently asked questions (FAQ),
    send mail to  or
    .

    ====================================================================    SUSE's security contact is  or .
    The  public key is listed below.
    ====================================================================

SuSE: 2005-049: php4/php5 Pear::XML_RPC code injection and PCRE integer overflow problems Security Update

August 30, 2005
This update fixes the following security issues in the PHP scripting This update fixes the following security issues in the PHP scripting language

Summary


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

______________________________________________________________________________

                        SUSE Security Announcement

        Package:                php4, php5
        Announcement ID:        SUSE-SA:2005:049
        Date:                   Tue, 30 Aug 2005 15:00:00 +0000
        Affected Products:      9.0, 9.1, 9.2, 9.3
                                SUSE Linux Enterprise Server 8, 9
        Vulnerability Type:     remote code execution
        Severity (1-10):        8
        SUSE Default Package:   yes
        Cross-References:       CAN-2005-2498
                                CAN-2005-2491


    Content of This Advisory:
        1) Security Vulnerability Resolved:
             Pear::XML_RPC code injection problem, pcre integer overflow
           Problem Description
        2) Solution or Work-Around
        3) Special Instructions and Notes
        4) Package Location and Checksums
        5) Pending Vulnerabilities, Solutions, and Work-Arounds:
            See SUSE Security Summary Report.
        6) Authenticity Verification and Additional Information

______________________________________________________________________________

1) Problem Description and Brief Discussion

   This update fixes the following security issues in the PHP scripting
   language.

   - Bugs in the PEAR::XML_RPC library allowed remote attackers to pass
     arbitrary PHP code to the eval() function (CAN-2005-1921,
     CAN-2005-2498).

     The Pear::XML_RPC library is not used by default in SUSE Linux, but
     might be used by third-party PHP applications.

   - A integer overflow bug was found in the PCRE (perl compatible regular
     expression) library which could be used by an attacker to potentially
     execute code. (CAN-2005-2491)

2) Solution or Work-Around

   Please install the updated packages.

3) Special Instructions and Notes

   Make sure you restart the web server using PHP after the update.

4) Package Location and Checksums

   The preferred method for installing security updates is to use the YaST
   Online Update (YOU) tool. YOU detects which updates are required and
   automatically performs the necessary steps to verify and install them.
   Alternatively, download the update packages for your distribution manually
   and verify their integrity by the methods listed in Section 6 of this
   announcement. Then install the packages using the command

     rpm -Fhv 

   to apply the update, replacing  with the filename of the
   downloaded RPM package.

   Our maintenance customers are notified individually. The packages are
   offered for installation from the maintenance web.


   x86 Platform:

   SUSE Linux 9.3:
             f4e6d7578b6ae62a0b49989a3be4ef4b
             79bb1fdc66068aba68a253d16a02f471
             08708573a0dee6ea412f7afc0d472244
             ffc0d7f665be377b1c9450f16d8b0b35
             44bbb9ec8f40b92030a591a718312ce1
             081168bede1cc4409c17fe71ea891f6e
             f6beca45181a6f92cba938b6b1009b39
             c35765443f99ee337e8df8b54414ef74
             9681a8e5dd6db224689d8e5dc6f07aff
             9f18c0bce655a1eda2fa9db9cb703e68
             d39bb57b5df06dc64e3cc5cf484c030c
             514561227c94e8af808dfb9d47a8143a
             a08670d24ea2af4e22425b9879804fa9
             9c374d9ed218a85399d5a529f8f97417
             4cba59009162137d5e4a79f0c355ec15
             a31dd5f81ebe25fc69b4a3a29321fed9
             4b1cf3f9ccfc1f4a546f188768a54da2
             4cddafbceded22b220e48542f6371337

   SUSE Linux 9.2:
             b5f30d4fcad5a1f8a3e5dfc9db519914
             eed1a644b3908e719d81359b96ef4244
             3a9fd735f7897fb97be921dee4afe850
             6145bf500d49378b1f7cd5441612ad92
             38c72905c9c47a6ab680faa781927020
             8483c7ce1b73710f03120fb7cf009740
             202af06b5ee93fd667a7484d01c3089b
             498f23a90eab4da6a06de67e44a84014
             254f0ee5ac6d04f244a8cfd171fdff57
             528b00aeb3433f5829cd070a84cfeeb9

   SUSE Linux 9.1:
             214e4ef40cb48c998342995cac9d04b8
             f2d4e625ea55fa7ead3a754238ca7078
             fabfae99a0462b49ec5f1109cd6820a9
             ca1aaef816f44495a90d4fb487a26524
             66fe3a880315e1de5d408a5dcaca3680
             c21383cbc809a455c7eff45b8f533f52
             21363ed91ae437ca66a97ba597c2529c
             ebdd8e83894392f455f57f8bf96022ea
             f6bf0f02c69fe67d2b229000bb5c93de
             a2b8fbb9a6f9720e332d311096280aa8
             7a82acc19b8817a5b80e87bacfab33c7
             654aa331a6353a34937d6688f8cb6d36
             fd388995234e536a8d72983f3eb51ce1
             d47c5fee9862e92daa317f48f3337b28
             29bd1f214d830de2f70c093ad428452b
   source rpm(s):
             dd586cc978292519a290d27439a9da28

   SUSE Linux 9.0:
             72dc636b72a3e8b8703eb3d6b770ca61
             a0934b5d7f27d2d86a9587dd5981e550
             8a9553c2157af21753305fc013bd4b75
             9dce9a4f911cd1deed07096d5c5be00a
             5fab53be54518170d3885459ee51232f
             fd0e4d8d4a938711bc2a93c50a5a1be9
   source rpm(s):
             f9f22aee983bbb30e2a10b4343155587

   x86-64 Platform:

   SUSE Linux 9.3:
             a3566598438cadf224fd5b1a126a6024
             c6186821c83c329729f282fb8ca34be8
             ac65da1e1109543f424e6abb1fa99201
             70c628abfaef3a4749c4683a9fa6de25
             3dde57064fcec2d5fbb5eb8397174f43
             be6b952045156e8e39286cf31567f8c2
             afcaf39f5dd99859f789e68d8183895d
             62d056349b1fffe351fb0d88c3d69905
             1352247dee304526e024d8c4132fc04c
             0b76af3f88a4482fc59b3e7ddba60ebd
             915b53c32abeff07e509c7480946ba40
             99df6f9e22a93b0ae6a07689d04af43e
             e0cdc636f1234231653f0cdc354272be
             6c25772c43098d4ceeba2637a06b21a0
             2621bf4f9a6582135e10e60861c16c73
             7a008af048763a61e05b5d90c94cdaa7
             408072d7b235721984593b2daf4cc56f
   source rpm(s):
             2becfb1be4d621a677305153b6aeb04e
             2ec1cf29732840e136d7291677a58c46

   SUSE Linux 9.2:
             b138dceb7fbc705676fc37c1959a7265
             d8b17ce13cc0ffd38ab340d1374c27e9
             89572dce1437f77010f224dde5f77b84
             af4ef7e10f30648c8d6397b3453eade5
             138673e37f145774abb545ff17b2d873
             0af41c67a8a227f2e59d47530b79aef4
             a267c09190f6782bd408f3b9d451755f
             400df3b11703fba3c363cb6cfd90425f
             a0b37ffe882338dd6ed727fd657f7180
   source rpm(s):
             b987cb8e60e74cac76b83a6b85092a13

   SUSE Linux 9.1:
             1088ec323766692fdf30252386dd17d5
             b32bec6f686d83cdff538c661c9bd693
             6a4a2ee9725a7cbeda50f0bf3c30e1b0
             eaace43d9273a5fbf79fa47af64cb764
             23ea7c1d4f9d4088201a39106062a169
             dd0df0fc61f5331bb7fa8d2fff929cff
             e14efdeda23c06aac65e55db83555328
             1a81b3b1c7b6562c330e5fd8afb33489
             4e5afde23ba37c5c83bcd2f4ea23e5a4
             3ec4a646f4254293af2423b1690e68c3
             70de23feb7e561f4f9225d82dd51ff6f
             de543ba0db1f755f16afa77a1ad6ad06
             973fcbda433eb8187b426ec93e8fefb2
             42c4cc25a00aa42b83aad8be9cbcc265
             5941a332be13d1a602d6bb2e48c7b188
   source rpm(s):
             2e021c18d66c00989a1fe019cb241064

   SUSE Linux 9.0:
             c83318085caf523c2a4afcf7e707aaf4
             f10309b963b542c0dedb3533c139bc9a
             19c7918452fdaee52677f3a7adad2863
             deebef74b38aca7af032deec065a8f5e
             9979f459d175849bd4eda540a8044c3a
             f15b60a9766e6d9fd405a854e71e9809
   source rpm(s):
             5bb5ca24643ef02c1e9b645a2656670c


______________________________________________________________________________

5) Pending Vulnerabilities, Solutions, and Work-Arounds:

   See SUSE Security Summary Report.
______________________________________________________________________________

6) Authenticity Verification and Additional Information

  - Announcement authenticity verification:

    SUSE security announcements are published via mailing lists and on Web
    sites. The authenticity and integrity of a SUSE security announcement is
    guaranteed by a cryptographic signature in each announcement. All SUSE
    security announcements are published with a valid signature.

    To verify the signature of the announcement, save it as text into a file
    and run the command

      gpg --verify 

    replacing  with the name of the file where you saved the
    announcement. The output for a valid signature looks like:

      gpg: Signature made  using RSA key ID 3D25D3D9
      gpg: Good signature from "SuSE Security Team "

    where  is replaced by the date the document was signed.

    If the security team's key is not contained in your key ring, you can
    import it from the first installation CD. To import the key, use the
    command

      gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc

  - Package authenticity verification:

    SUSE update packages are available on many mirror FTP servers all over the
    world. While this service is considered valuable and important to the free
    and open source software community, the authenticity and the integrity of
    a package needs to be verified to ensure that it has not been tampered
    with.

    There are two verification methods that can be used independently from
    each other to prove the authenticity of a downloaded file or RPM package:

    1) Using the internal gpg signatures of the rpm package
    2) MD5 checksums as provided in this announcement

    1) The internal rpm package signatures provide an easy way to verify the
       authenticity of an RPM package. Use the command

        rpm -v --checksig 

       to verify the signature of the package, replacing  with the
       filename of the RPM package downloaded. The package is unmodified if it
       contains a valid signature from build@suse.de with the key ID 9C800ACA.

       This key is automatically imported into the RPM database (on
       RPMv4-based distributions) and the gpg key ring of 'root' during
       installation. You can also find it on the first installation CD and at
       the end of this announcement.

    2) If you need an alternative means of verification, use the md5sum
       command to verify the authenticity of the packages. Execute the command

         md5sum 

       after you downloaded the file from a SUSE FTP server or its mirrors.
       Then compare the resulting md5sum with the one that is listed in the
       SUSE security announcement. Because the announcement containing the
       checksums is cryptographically signed (by security@suse.de), the
       checksums show proof of the authenticity of the package if the
       signature of the announcement is valid. Note that the md5 sums
       published in the SUSE Security Announcements are valid for the
       respective packages only. Newer versions of these packages cannot be
       verified.

  - SUSE runs two security mailing lists to which any interested party may
    subscribe:

    suse-security@suse.com
        -   General Linux and SUSE security discussion.
            All SUSE security announcements are sent to this list.
            To subscribe, send an e-mail to
                .

    suse-security-announce@suse.com
        -   SUSE's announce-only mailing list.
            Only SUSE's security announcements are sent to this list.
            To subscribe, send an e-mail to
                .

    For general information or the frequently asked questions (FAQ),
    send mail to  or
    .

    ====================================================================    SUSE's security contact is  or .
    The  public key is listed below.
    ====================================================================

References

Severity

Related News