Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Ubuntu: 2163-1 Moderate Security Advisory for PHP DoS Vulnerability

Ubuntu Large Esm H500
PHP could be made to crash if it processed a specially crafted file.
=========================================================================Ubuntu Security Notice USN-2163-1
April 07, 2014

php5 vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.10
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

PHP could be made to crash if it processed a specially crafted file.

Software Description:
- php5: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP's embedded libmagic library incorrectly handled
PE executables. An attacker could use this issue to cause PHP to crash,
resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  libapache2-mod-php5             5.5.3+dfsg-1ubuntu2.3
  php5-cgi                        5.5.3+dfsg-1ubuntu2.3
  php5-cli                        5.5.3+dfsg-1ubuntu2.3

Ubuntu 12.10:
  libapache2-mod-php5             5.4.6-1ubuntu1.8
  php5-cgi                        5.4.6-1ubuntu1.8
  php5-cli                        5.4.6-1ubuntu1.8

Ubuntu 12.04 LTS:
  libapache2-mod-php5             5.3.10-1ubuntu3.11
  php5-cgi                        5.3.10-1ubuntu3.11
  php5-cli                        5.3.10-1ubuntu3.11

Ubuntu 10.04 LTS:
  libapache2-mod-php5             5.3.2-1ubuntu4.24
  php5-cgi                        5.3.2-1ubuntu4.24
  php5-cli                        5.3.2-1ubuntu4.24

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2163-1
  CVE-2014-2270

Package Information:
  https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.3
  https://launchpad.net/ubuntu/+source/php5/5.4.6-1ubuntu1.8
  https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.11
  https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.24


Ubuntu: 2163-1 Moderate Security Advisory for PHP DoS Vulnerability

ubuntu
Calendar Grey April 7, 2014
Dist Ubuntu Esm H88
The approach that PHP takes in managing files is problematic, leading to system failures and risks of Denial of Service attacks. Upgrade your Ubuntu system to enhance its security.
PHP could be made to crash if it processed a specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: libapache2-mod-php5 5.5.3+dfsg-1ubuntu2.3 php5-cgi 5.5.3+dfsg-1ubuntu2.3 php5-cli 5.5.3+dfsg-1ubuntu2.3 Ubuntu 12.10: libapache2-mod-php5 5.4.6-1ubuntu1.8 php5-cgi 5.4.6-1ubuntu1.8 php5-cli 5.4.6-1ubuntu1.8 Ubuntu 12.04 LTS: libapache2-mod-php5 5.3.10-1ubuntu3.11 php5-cgi 5.3.10-1ubuntu3.11 php5-cli 5.3.10-1ubuntu3.11 Ubuntu 10.04 LTS: libapache2-mod-php5 5.3.2-1ubuntu4.24 php5-cgi 5.3.2-1ubuntu4.24 php5-cli 5.3.2-1ubuntu4.24 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2163-1

CVE-2014-2270

April 07, 2014

Package Information

https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.3 https://launchpad.net/ubuntu/+source/php5/5.4.6-1ubuntu1.8 https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.11 https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.24

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here