Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 13.04/12.10 LTS: USN-1905-1 High Severity: PHP Denial Of Service

ubuntu
Calendar Grey July 16, 2013
Scroller Ubuntu
A range of vulnerabilities in PHP were addressed in Ubuntu's USN-1905-2 announcement. It is critical that you update your systems promptly to reduce potential threats.
Several security issues were fixed in PHP.

Summary

Several security issues were fixed in PHP.

Software Description:

- php5: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP incorrectly handled the xml_parse_into_struct

function. If a PHP application parsed untrusted XML, an attacker could use

this flaw with a specially-crafted XML document to cause PHP to crash,

resulting in a denial of service, or to possibly execute arbitrary code.

(CVE-2013-4113)

It was discovered that PHP incorrectly handled the jdtojewish function. An

attacker could use this flaw to cause PHP to crash, resulting in a denial

of service. (CVE-2013-4635)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  libapache2-mod-php5             5.4.9-4ubuntu2.2
  php5-cgi                        5.4.9-4ubuntu2.2
  php5-cli                        5.4.9-4ubuntu2.2

Ubuntu 12.10:
  libapache2-mod-php5             5.4.6-1ubuntu1.3
  php5-cgi                        5.4.6-1ubuntu1.3
  php5-cli                        5.4.6-1ubuntu1.3

Ubuntu 12.04 LTS:
  libapache2-mod-php5             5.3.10-1ubuntu3.7
  php5-cgi                        5.3.10-1ubuntu3.7
  php5-cli                        5.3.10-1ubuntu3.7

Ubuntu 10.04 LTS:
  libapache2-mod-php5             5.3.2-1ubuntu4.20
  php5-cgi                        5.3.2-1ubuntu4.20
  php5-cli                        5.3.2-1ubuntu4.20

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1905-1

CVE-2013-4113, CVE-2013-4635

July 16, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.