SuSE: 2002:007 Critical: mod_php Remote Command Execution
Multiple critical remote vulnerabilities exist in several versions of PHP. Several flaws in the way PHP handles multipart/form-data POST requests have been found.
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Find the information you need for your favorite open source distribution .
Multiple critical remote vulnerabilities exist in several versions of PHP. Several flaws in the way PHP handles multipart/form-data POST requests have been found.
We re-release SuSE Security Announcement SuSE-SA:2002:005 with the new announcement ID SuSE-SA:2002:006 due to minor packaging errors that can result in a malfunction of the printing subsystem.
The buffer overflow could be exploited by a remote attacker as long as their IP address is allowed to connect to the CUPS server. This advisory has been retracted due to errors in the binary packages.
There exist several signedness bugs within the rsync program which allow remote attackers to write 0-bytes to almost arbitrary stack-locations, therefore being able to control the programflow and obtaining a shell remotely.
The at command may crash as a result of a surplus call to free(). The cause of the crash is a heap corruption that is exploitable under certain circumstances since the /usr/bin/at command is installed setuid root.