Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
98

Red Hat Application Stack v2.3 RHSA-2009:1067-01 Moderate Memory Issues

Red Hat Application Stack v2.3 is now available. This update fixes several security issues and adds various enhancements. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Application Stack v2.3 security and enhancement update Advisory ID: RHSA-2009:1067-01 Product: Red Hat Application Stack Advisory URL: https://access.redhat.com/errata/RHSA-2009:1067.html Issue date: 2009-05-26 CVE Names: CVE-2008-3963 CVE-2008-4098 CVE-2009-0663 CVE-2009-0922 CVE-2009-1341 ==================================================================== 1. Summary: Red Hat Application Stack v2.3 is now available. This update fixes several security issues and adds various enhancements. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Application Stack v2 for Enterprise Linux (v.5) - i386, x86_64 3. Description: Red Hat Application Stack v2.3 is an integrated open source application stack, that includes Red Hat Enterprise Linux 5 and JBoss Enterprise Application Platform (EAP). JBoss EAP is provided through the JBoss EAP channels on the Red Hat Network. This update fixes the following security issues: A heap-based buffer overflow flaw was discovered in the perl-DBD-Pg pg_getline function implementation. If the pg_getline or getline functions read large, untrusted records from a database, it could cause an application using these functions to crash or, possibly, execute arbitrary code. (CVE-2009-0663) Note: After installing this update, pg_getline may return more data than specified by its second argument, as this argument will be ignored. This is consistent with current upstream behavior. Previously, the length limit (the secondargument) was not enforced, allowing a buffer overflow. A memory leak flaw was found in the perl-DBD-Pg function performing the de-quoting of BYTEA type values acquired from a database. An attacker able to cause an application using perl-DBD-Pg to perform a large number of SQL queries returning BYTEA records, could cause the application to use excessive amounts of memory or, possibly, crash. (CVE-2009-1341) MySQL was updated to version 5.0.79, fixing the following security issues: A flaw was found in the way MySQL handles an empty bit-string literal. A remote, authenticated attacker could crash the MySQL server daemon (mysqld) if they used an empty bit-string literal in an SQL statement. This issue only caused a temporary denial of service, as the MySQL daemon was automatically restarted after the crash. (CVE-2008-3963) It was discovered that the Red Hat Security Advisory RHSA-2008:0505, for Red Hat Application Stack v2.1, provided an incomplete fix for the flaw where MySQL did not correctly check directories used as arguments for the DATA DIRECTORY and INDEX DIRECTORY directives. Using this flaw, an authenticated attacker could elevate their access privileges to tables created by other database users. Note: This attack does not work on existing tables. An attacker can only elevate their access to another user's tables as the tables are created. As well, the names of these created tables need to be predicted correctly for this attack to succeed. (CVE-2008-4098) PostgreSQL was updated to version 8.2.13, fixing the following security issue: A flaw was found in the way PostgreSQL handles encoding conversion. A remote, authenticated user could trigger an encoding conversion failure, possibly leading to a temporary denial of service. (CVE-2009-0922) Also, the following packages have been updated: * httpd to 2.2.11 * mysql-connector-odbc to 3.51.27r695 * perl-DBD-MySQL to 4.010-1.el5s2 * php to 5.2.9 * postgresql-jdbc to 8.2.509 * postgresqlclient81 to 8.1.17 All users should upgrade to these updatedpackages, which resolve these issues. Users must restart the individual services, including postgresql, mysqld, and httpd, for this update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 454077 - CVE-2008-4098 mysql: incomplete upstream fix for CVE-2008-2079 462071 - CVE-2008-3963 MySQL: Using an empty binary value leads to server crash 488156 - CVE-2009-0922 postgresql: potential DoS due to conversion functions 497367 - CVE-2009-0663 perl-DBD-Pg: pg_getline buffer overflow 497503 - CVE-2009-1341 perl-DBD-Pg: dequote_bytea memory leak 6. Package List: Red Hat Application Stack v2 for Enterprise Linux(v.5): Source: i386: httpd-2.2.11-2.el5s2.i386.rpm httpd-debuginfo-2.2.11-2.el5s2.i386.rpm httpd-devel-2.2.11-2.el5s2.i386.rpm httpd-manual-2.2.11-2.el5s2.i386.rpm mod_jk-ap20-1.2.28-2.el5s2.i386.rpm mod_jk-debuginfo-1.2.28-2.el5s2.i386.rpm mod_ssl-2.2.11-2.el5s2.i386.rpm mysql-5.0.79-2.el5s2.i386.rpm mysql-bench-5.0.79-2.el5s2.i386.rpm mysql-cluster-5.0.79-2.el5s2.i386.rpm mysql-connector-odbc-3.51.27r695-1.el5s2.i386.rpm mysql-connector-odbc-debuginfo-3.51.27r695-1.el5s2.i386.rpm mysql-debuginfo-5.0.79-2.el5s2.i386.rpm mysql-devel-5.0.79-2.el5s2.i386.rpm mysql-libs-5.0.79-2.el5s2.i386.rpm mysql-server-5.0.79-2.el5s2.i386.rpm mysql-test-5.0.79-2.el5s2.i386.rpm perl-DBD-MySQL-4.010-1.el5s2.i386.rpm perl-DBD-MySQL-debuginfo-4.010-1.el5s2.i386.rpm perl-DBD-Pg-1.49-5.el5s2.i386.rpm perl-DBD-Pg-debuginfo-1.49-5.el5s2.i386.rpm php-5.2.9-2.el5s2.i386.rpm php-bcmath-5.2.9-2.el5s2.i386.rpm php-cli-5.2.9-2.el5s2.i386.rpm php-common-5.2.9-2.el5s2.i386.rpm php-dba-5.2.9-2.el5s2.i386.rpm php-debuginfo-5.2.9-2.el5s2.i386.rpm php-devel-5.2.9-2.el5s2.i386.rpm php-gd-5.2.9-2.el5s2.i386.rpm php-imap-5.2.9-2.el5s2.i386.rpm php-ldap-5.2.9-2.el5s2.i386.rpm php-mbstring-5.2.9-2.el5s2.i386.rpm php-mysql-5.2.9-2.el5s2.i386.rpm php-ncurses-5.2.9-2.el5s2.i386.rpm php-odbc-5.2.9-2.el5s2.i386.rpm php-pdo-5.2.9-2.el5s2.i386.rpm php-pgsql-5.2.9-2.el5s2.i386.rpm php-snmp-5.2.9-2.el5s2.i386.rpm php-soap-5.2.9-2.el5s2.i386.rpm php-xml-5.2.9-2.el5s2.i386.rpm php-xmlrpc-5.2.9-2.el5s2.i386.rpm postgresql-8.2.13-2.el5s2.i386.rpm postgresql-contrib-8.2.13-2.el5s2.i386.rpm postgresql-debuginfo-8.2.13-2.el5s2.i386.rpm postgresql-devel-8.2.13-2.el5s2.i386.rpm postgresql-docs-8.2.13-2.el5s2.i386.rpm postgresql-jdbc-8.2.509-2jpp.el5s2.i386.rpm postgresql-jdbc-debuginfo-8.2.509-2jpp.el5s2.i386.rpm postgresql-libs-8.2.13-2.el5s2.i386.rpm postgresql-plperl-8.2.13-2.el5s2.i386.rpm postgresql-plpython-8.2.13-2.el5s2.i386.rpm postgresql-pltcl-8.2.13-2.el5s2.i386.rpm postgresql-python-8.2.13-2.el5s2.i386.rpm postgresql-server-8.2.13-2.el5s2.i386.rpm postgresql-tcl-8.2.13-2.el5s2.i386.rpm postgresql-test-8.2.13-2.el5s2.i386.rpm postgresqlclient81-8.1.17-1.el5s2.i386.rpm postgresqlclient81-debuginfo-8.1.17-1.el5s2.i386.rpm x86_64: httpd-2.2.11-2.el5s2.x86_64.rpm httpd-debuginfo-2.2.11-2.el5s2.i386.rpm httpd-debuginfo-2.2.11-2.el5s2.x86_64.rpm httpd-devel-2.2.11-2.el5s2.i386.rpm httpd-devel-2.2.11-2.el5s2.x86_64.rpm httpd-manual-2.2.11-2.el5s2.x86_64.rpm mod_jk-ap20-1.2.28-2.el5s2.x86_64.rpm mod_jk-debuginfo-1.2.28-2.el5s2.x86_64.rpm mod_ssl-2.2.11-2.el5s2.x86_64.rpm mysql-5.0.79-2.el5s2.i386.rpm mysql-5.0.79-2.el5s2.x86_64.rpm mysql-bench-5.0.79-2.el5s2.x86_64.rpm mysql-cluster-5.0.79-2.el5s2.x86_64.rpm mysql-connector-odbc-3.51.27r695-1.el5s2.x86_64.rpm mysql-connector-odbc-debuginfo-3.51.27r695-1.el5s2.x86_64.rpm mysql-debuginfo-5.0.79-2.el5s2.i386.rpm mysql-debuginfo-5.0.79-2.el5s2.x86_64.rpm mysql-devel-5.0.79-2.el5s2.i386.rpm mysql-devel-5.0.79-2.el5s2.x86_64.rpm mysql-libs-5.0.79-2.el5s2.i386.rpm mysql-libs-5.0.79-2.el5s2.x86_64.rpm mysql-server-5.0.79-2.el5s2.x86_64.rpm mysql-test-5.0.79-2.el5s2.x86_64.rpm perl-DBD-MySQL-4.010-1.el5s2.x86_64.rpm perl-DBD-MySQL-debuginfo-4.010-1.el5s2.x86_64.rpm perl-DBD-Pg-1.49-5.el5s2.x86_64.rpm perl-DBD-Pg-debuginfo-1.49-5.el5s2.x86_64.rpm php-5.2.9-2.el5s2.x86_64.rpm php-bcmath-5.2.9-2.el5s2.x86_64.rpm php-cli-5.2.9-2.el5s2.x86_64.rpm php-common-5.2.9-2.el5s2.x86_64.rpm php-dba-5.2.9-2.el5s2.x86_64.rpm php-debuginfo-5.2.9-2.el5s2.x86_64.rpm php-devel-5.2.9-2.el5s2.x86_64.rpm php-gd-5.2.9-2.el5s2.x86_64.rpm php-imap-5.2.9-2.el5s2.x86_64.rpm php-ldap-5.2.9-2.el5s2.x86_64.rpm php-mbstring-5.2.9-2.el5s2.x86_64.rpm php-mysql-5.2.9-2.el5s2.x86_64.rpm php-ncurses-5.2.9-2.el5s2.x86_64.rpm php-odbc-5.2.9-2.el5s2.x86_64.rpm php-pdo-5.2.9-2.el5s2.x86_64.rpm php-pgsql-5.2.9-2.el5s2.x86_64.rpm php-snmp-5.2.9-2.el5s2.x86_64.rpm php-soap-5.2.9-2.el5s2.x86_64.rpm php-xml-5.2.9-2.el5s2.x86_64.rpm php-xmlrpc-5.2.9-2.el5s2.x86_64.rpm postgresql-8.2.13-2.el5s2.x86_64.rpm postgresql-contrib-8.2.13-2.el5s2.x86_64.rpm postgresql-debuginfo-8.2.13-2.el5s2.i386.rpm postgresql-debuginfo-8.2.13-2.el5s2.x86_64.rpm postgresql-devel-8.2.13-2.el5s2.i386.rpm postgresql-devel-8.2.13-2.el5s2.x86_64.rpm postgresql-docs-8.2.13-2.el5s2.x86_64.rpm postgresql-jdbc-8.2.509-2jpp.el5s2.x86_64.rpm postgresql-jdbc-debuginfo-8.2.509-2jpp.el5s2.x86_64.rpm postgresql-libs-8.2.13-2.el5s2.i386.rpm postgresql-libs-8.2.13-2.el5s2.x86_64.rpm postgresql-plperl-8.2.13-2.el5s2.x86_64.rpm postgresql-plpython-8.2.13-2.el5s2.x86_64.rpm postgresql-pltcl-8.2.13-2.el5s2.x86_64.rpm postgresql-python-8.2.13-2.el5s2.x86_64.rpm postgresql-server-8.2.13-2.el5s2.x86_64.rpm postgresql-tcl-8.2.13-2.el5s2.x86_64.rpm postgresql-test-8.2.13-2.el5s2.x86_64.rpm postgresqlclient81-8.1.17-1.el5s2.i386.rpm postgresqlclient81-8.1.17-1.el5s2.x86_64.rpm postgresqlclient81-debuginfo-8.1.17-1.el5s2.i386.rpm postgresqlclient81-debuginfo-8.1.17-1.el5s2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2008-3963 https://www.cve.org/CVERecord?id=CVE-2008-4098 https://www.cve.org/CVERecord?id=CVE-2009-0663 https://www.cve.org/CVERecord?id=CVE-2009-0922 https://www.cve.org/CVERecord?id=CVE-2009-1341 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFKHCmoXlSAg2UNWIIRAupAAJ4vMxFqUdphdOG/7P/3lS7z3S/1twCfe3bJ fMo7KqCYDMTARro6tAQY1cI=2EKN -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent refresh of Red Hat Application Stack v2.3 addresses multiple security vulnerabilities and introduces various improvements.. Red Hat Application Stack, security update, application fixes. . LinuxSecurity.com Team

Calendar 2 May 26, 2009 Red Hat
98

Red Hat: RHSA-2009:0446-01 Important: Info Leak in mod_jk Package

An updated mod_jk package that fixes a security issue is now available for Red Hat Application Stack v2. This update has been rated as having important security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Important: mod_jk security update Advisory ID: RHSA-2009:0446-01 Product: Red Hat Application Stack Advisory URL: https://access.redhat.com/errata/RHSA-2009:0446.html Issue date: 2009-04-23 CVE Names: CVE-2008-5519 ==================================================================== 1. Summary: An updated mod_jk package that fixes a security issue is now available for Red Hat Application Stack v2. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Application Stack v2 for Enterprise Linux (v.5) - i386, x86_64 3. Description: mod_jk is an Apache Tomcat connector that allows Apache Tomcat and the Apache HTTP Server to communicate with each other. An information disclosure flaw was found in mod_jk. In certain situations, if a faulty client set the "Content-Length" header without providing data, or if a user sent repeated requests very quickly, one user may view a response intended for another user. (CVE-2008-5519) As well, the sample configuration files provided in the documentation have been updated to reflect recommended practice. All mod_jk users are advised to upgrade to this updated package. It provides mod_jk 1.2.28, which is not vulnerable to this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 490201 - CVE-2008-5519 mod_jk: session information leak 6. PackageList: Red Hat Application Stack v2 for Enterprise Linux (v.5): Source: i386: mod_jk-ap20-1.2.28-1.el5s2.i386.rpm mod_jk-debuginfo-1.2.28-1.el5s2.i386.rpm x86_64: mod_jk-ap20-1.2.28-1.el5s2.x86_64.rpm mod_jk-debuginfo-1.2.28-1.el5s2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2008-5519 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2009 Red Hat, Inc. . Critical mod_jk patch released for Red Hat Application Stack v2 to mitigate security vulnerabilities promptly.. mod_jk fix, Red Hat update, important security patch, application stack update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 23, 2009 Important Red Hat
98

Red Hat RHSA-2009-0350-01 Moderate: PHP Buffer Overflow and DoS Fixes

Updated php packages that fix several security issues are now available for Red Hat Application Stack v2. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: php security update Advisory ID: RHSA-2009:0350-01 Product: Red Hat Application Stack Advisory URL: https://access.redhat.com/errata/RHSA-2009:0350.html Issue date: 2009-04-14 CVE Names: CVE-2008-3658 CVE-2008-3660 CVE-2008-5498 CVE-2008-5557 CVE-2008-5658 CVE-2008-5814 CVE-2009-0754 CVE-2009-1271 ==================================================================== 1. Summary: Updated php packages that fix several security issues are now available for Red Hat Application Stack v2. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Application Stack v2 for Enterprise Linux (v.5) - i386, x86_64 3. Description: PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Web server. A heap-based buffer overflow flaw was found in PHP's mbstring extension. A remote attacker able to pass arbitrary input to a PHP script using mbstring conversion functions could cause the PHP interpreter to crash or, possibly, execute arbitrary code. (CVE-2008-5557) A flaw was found in the handling of the "mbstring.func_overload" configuration setting. A value set for one virtual host, or in a user's .htaccess file, was incorrectly applied to other virtual hosts on the same server, causing the handling of multibyte character strings to not work correctly. (CVE-2009-0754) A directory traversal flaw was found in PHP's ZipArchive::extractTo function. If PHP is used to extract a malicious ZIP archive, it could allow an attacker to write arbitrary filesanywhere the PHP process has write permissions. (CVE-2008-5658) A buffer overflow flaw was found in PHP's imageloadfont function. If a PHP script allowed a remote attacker to load a carefully crafted font file, it could cause the PHP interpreter to crash or, possibly, execute arbitrary code. (CVE-2008-3658) A flaw was found in the way PHP handled certain file extensions when running in FastCGI mode. If the PHP interpreter was being executed via FastCGI, a remote attacker could create a request which would cause the PHP interpreter to crash. (CVE-2008-3660) A memory disclosure flaw was found in the PHP gd extension's imagerotate function. A remote attacker able to pass arbitrary values as the "background color" argument of the function could, possibly, view portions of the PHP interpreter's memory. (CVE-2008-5498) A cross-site scripting flaw was found in a way PHP reported errors for invalid cookies. If the PHP interpreter had "display_errors" enabled, a remote attacker able to set a specially-crafted cookie on a victim's system could possibly inject arbitrary HTML into an error message generated by PHP. (CVE-2008-5814) A flaw was found in PHP's json_decode function. A remote attacker could use this flaw to create a specially-crafted string which could cause the PHP interpreter to crash while being decoded in a PHP script. (CVE-2009-1271) All php users are advised to upgrade to these updated packages, which contain backported patches to resolve these issues. The httpd web server must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 459529 - CVE-2008-3658 php: buffer overflow in the imageloadfont function in gd extension 459572 - CVE-2008-3660 php: FastCGI module DoS via multiple dots preceding theextension 474824 - CVE-2008-5658 php: ZipArchive::extractTo() Directory Traversal Vulnerability 478425 - CVE-2008-5498 php: libgd imagerotate() array index error memory disclosure 478848 - CVE-2008-5557 php: Heap-based buffer overflow in the mbstring extension via crafted string containing a HTML entity (arb code execution) 479272 - CVE-2009-0754 PHP mbstring.func_overload web server denial of service 480167 - CVE-2008-5814 php: XSS via PHP error messages 494530 - CVE-2009-1271 php: crash on malformed input in json_decode() 6. Package List: Red Hat Application Stack v2 for Enterprise Linux (v.5): Source: i386: php-5.2.6-4.el5s2.i386.rpm php-bcmath-5.2.6-4.el5s2.i386.rpm php-cli-5.2.6-4.el5s2.i386.rpm php-common-5.2.6-4.el5s2.i386.rpm php-dba-5.2.6-4.el5s2.i386.rpm php-debuginfo-5.2.6-4.el5s2.i386.rpm php-devel-5.2.6-4.el5s2.i386.rpm php-gd-5.2.6-4.el5s2.i386.rpm php-imap-5.2.6-4.el5s2.i386.rpm php-ldap-5.2.6-4.el5s2.i386.rpm php-mbstring-5.2.6-4.el5s2.i386.rpm php-mysql-5.2.6-4.el5s2.i386.rpm php-ncurses-5.2.6-4.el5s2.i386.rpm php-odbc-5.2.6-4.el5s2.i386.rpm php-pdo-5.2.6-4.el5s2.i386.rpm php-pgsql-5.2.6-4.el5s2.i386.rpm php-snmp-5.2.6-4.el5s2.i386.rpm php-soap-5.2.6-4.el5s2.i386.rpm php-xml-5.2.6-4.el5s2.i386.rpm php-xmlrpc-5.2.6-4.el5s2.i386.rpm x86_64: php-5.2.6-4.el5s2.x86_64.rpm php-bcmath-5.2.6-4.el5s2.x86_64.rpm php-cli-5.2.6-4.el5s2.x86_64.rpm php-common-5.2.6-4.el5s2.x86_64.rpm php-dba-5.2.6-4.el5s2.x86_64.rpm php-debuginfo-5.2.6-4.el5s2.x86_64.rpm php-devel-5.2.6-4.el5s2.x86_64.rpm php-gd-5.2.6-4.el5s2.x86_64.rpm php-imap-5.2.6-4.el5s2.x86_64.rpm php-ldap-5.2.6-4.el5s2.x86_64.rpm php-mbstring-5.2.6-4.el5s2.x86_64.rpm php-mysql-5.2.6-4.el5s2.x86_64.rpm php-ncurses-5.2.6-4.el5s2.x86_64.rpm php-odbc-5.2.6-4.el5s2.x86_64.rpm php-pdo-5.2.6-4.el5s2.x86_64.rpm php-pgsql-5.2.6-4.el5s2.x86_64.rpm php-snmp-5.2.6-4.el5s2.x86_64.rpm php-soap-5.2.6-4.el5s2.x86_64.rpm php-xml-5.2.6-4.el5s2.x86_64.rpm php-xmlrpc-5.2.6-4.el5s2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2008-3658 https://www.cve.org/CVERecord?id=CVE-2008-3660 https://www.cve.org/CVERecord?id=CVE-2008-5498 https://www.cve.org/CVERecord?id=CVE-2008-5557 https://www.cve.org/CVERecord?id=CVE-2008-5658 https://www.cve.org/CVERecord?id=CVE-2008-5814 https://www.cve.org/CVERecord?id=CVE-2009-0754 https://www.cve.org/CVERecord?id=CVE-2009-1271 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFJ5NAgXlSAg2UNWIIRAtJhAKCCKdjXCXkz0PeZUk5q0S3rsSf53gCfc/vm fj9YjQ5kUoICJShHZQfaHY8=eevn -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent PHP patch addresses vulnerabilities including integer overflow, file inclusion, and denial-of-service attacks for CentOS platforms.. php Update, Red Hat Security, Application Stack, Buffer Overflow, DoS Risk. . LinuxSecurity.com Team

Calendar 2 Apr 14, 2009 Red Hat
98

Red Hat: RHSA-2008:0510-01 Moderate: MySQL Privilege Escalation

Red Hat Application Stack v1.3 is now available. This update fixes a security issue and adds several enhancements. This updated has been rated as having moderate security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Application Stack v1.3 security and enhancement update Advisory ID: RHSA-2008:0510-01 Product: Red Hat Application Stack Advisory URL: https://access.redhat.com/errata/RHSA-2008:0510.html Issue date: 2008-07-02 CVE Names: CVE-2008-2079 ==================================================================== 1. Summary: Red Hat Application Stack v1.3 is now available. This update fixes a security issue and adds several enhancements. This updated has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Application Stack v1 for Enterprise Linux AS (v.4) - i386, x86_64 Red Hat Application Stack v1 for Enterprise Linux ES (v.4) - i386, x86_64 3. Description: The Red Hat Application Stack is an integrated open source application stack, and includes JBoss Enterprise Application Platform (EAP). Starting with this update, JBoss EAP is no longer provided via the Application Stack channels. Instead, all Application Stack customers are automatically entitled to the JBoss EAP channels. This ensures all users have immediate access to JBoss EAP packages when they are released, ensuring lesser wait for security and critical patches. As a result, you must MANUALLY subscribe to the appropriate JBoss EAP channel, as all further JBoss EAP updates will only go to that channel. This update also entitles all customers to the JBoss EAP 4.3.0 channels. Users receive support for JBoss EAP 4.3.0 if they choose to install it. Important: downgrading from JBoss EAP 4.3.0 to 4.2.0 is unsupported. MySQL was updated toversion 5.0.50sp1a, fixing the following security issue: MySQL did not correctly check directories used as arguments for the DATA DIRECTORY and INDEX DIRECTORY directives. Using this flaw, an authenticated attacker could elevate their access privileges to tables created by other database users. Note: this attack does not work on existing tables. An attacker can only elevate their access to another user's tables as the tables are created. As well, the names of these created tables need to be predicted correctly for this attack to succeed. (CVE-2008-2079) The following packages are updated: * httpd to 2.0.63 * mod_jk to 1.2.26 * the MySQL Connector/ODBC to 3.51.24r1071 * perl-DBD-MySQL to 4.006 * perl-DBI to 1.604 * postgresqlclient7 to 7.4.19 * postgresql-jdbc to 8.1.412 * unixODBC to 2.2.12 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 445222 - CVE-2008-2079 mysql: privilege escalation via DATA/INDEX DIRECTORY directives 6. Package List: Red Hat Application Stack v1 for Enterprise Linux AS(v.4): Source: i386: httpd-2.0.63-2.el4s1.2.i386.rpm httpd-debuginfo-2.0.63-2.el4s1.2.i386.rpm httpd-devel-2.0.63-2.el4s1.2.i386.rpm httpd-manual-2.0.63-2.el4s1.2.i386.rpm mod_jk-ap20-1.2.26-1.el4s1.1.i386.rpm mod_jk-debuginfo-1.2.26-1.el4s1.1.i386.rpm mod_jk-manual-1.2.26-1.el4s1.1.i386.rpm mod_ssl-2.0.63-2.el4s1.2.i386.rpm mysql-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-bench-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-cluster-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-connector-odbc-3.51.24r1071-1.el4s1.1.i386.rpm mysql-connector-odbc-debuginfo-3.51.24r1071-1.el4s1.1.i386.rpm mysql-debuginfo-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-devel-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-libs-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-server-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-test-5.0.50sp1a-2.el4s1.1.i386.rpm perl-DBD-MySQL-4.006-1.el4.i386.rpm perl-DBD-MySQL-debuginfo-4.006-1.el4.i386.rpm perl-DBI-1.604-1.el4s1.i386.rpm perl-DBI-debuginfo-1.604-1.el4s1.i386.rpm php-5.1.6-3.el4s1.9.i386.rpm php-bcmath-5.1.6-3.el4s1.9.i386.rpm php-cli-5.1.6-3.el4s1.9.i386.rpm php-common-5.1.6-3.el4s1.9.i386.rpm php-dba-5.1.6-3.el4s1.9.i386.rpm php-debuginfo-5.1.6-3.el4s1.9.i386.rpm php-devel-5.1.6-3.el4s1.9.i386.rpm php-gd-5.1.6-3.el4s1.9.i386.rpm php-imap-5.1.6-3.el4s1.9.i386.rpm php-ldap-5.1.6-3.el4s1.9.i386.rpm php-mbstring-5.1.6-3.el4s1.9.i386.rpm php-mysql-5.1.6-3.el4s1.9.i386.rpm php-ncurses-5.1.6-3.el4s1.9.i386.rpm php-odbc-5.1.6-3.el4s1.9.i386.rpm php-pdo-5.1.6-3.el4s1.9.i386.rpm php-pgsql-5.1.6-3.el4s1.9.i386.rpm php-snmp-5.1.6-3.el4s1.9.i386.rpm php-soap-5.1.6-3.el4s1.9.i386.rpm php-xml-5.1.6-3.el4s1.9.i386.rpm php-xmlrpc-5.1.6-3.el4s1.9.i386.rpm postgresql-jdbc-8.1.412-1jpp.el4s1.1.i386.rpm postgresql-jdbc-debuginfo-8.1.412-1jpp.el4s1.1.i386.rpm postgresqlclient7-7.4.19-1.el4s1.1.i386.rpm postgresqlclient7-debuginfo-7.4.19-1.el4s1.1.i386.rpm unixODBC-2.2.12-6.el4s1.1.i386.rpm unixODBC-debuginfo-2.2.12-6.el4s1.1.i386.rpm unixODBC-devel-2.2.12-6.el4s1.1.i386.rpm unixODBC-kde-2.2.12-6.el4s1.1.i386.rpm x86_64: httpd-2.0.63-2.el4s1.2.x86_64.rpm httpd-debuginfo-2.0.63-2.el4s1.2.x86_64.rpm httpd-devel-2.0.63-2.el4s1.2.x86_64.rpm httpd-manual-2.0.63-2.el4s1.2.x86_64.rpm mod_jk-ap20-1.2.26-1.el4s1.1.x86_64.rpm mod_jk-debuginfo-1.2.26-1.el4s1.1.x86_64.rpm mod_jk-manual-1.2.26-1.el4s1.1.x86_64.rpm mod_ssl-2.0.63-2.el4s1.2.x86_64.rpm mysql-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-bench-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-cluster-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-connector-odbc-3.51.24r1071-1.el4s1.1.x86_64.rpm mysql-connector-odbc-debuginfo-3.51.24r1071-1.el4s1.1.x86_64.rpm mysql-debuginfo-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-debuginfo-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-devel-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-libs-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-libs-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-server-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-test-5.0.50sp1a-2.el4s1.1.x86_64.rpm perl-DBD-MySQL-4.006-1.el4.x86_64.rpm perl-DBD-MySQL-debuginfo-4.006-1.el4.x86_64.rpm perl-DBI-1.604-1.el4s1.x86_64.rpm perl-DBI-debuginfo-1.604-1.el4s1.x86_64.rpm php-5.1.6-3.el4s1.9.x86_64.rpm php-bcmath-5.1.6-3.el4s1.9.x86_64.rpm php-cli-5.1.6-3.el4s1.9.x86_64.rpm php-common-5.1.6-3.el4s1.9.x86_64.rpm php-dba-5.1.6-3.el4s1.9.x86_64.rpm php-debuginfo-5.1.6-3.el4s1.9.x86_64.rpm php-devel-5.1.6-3.el4s1.9.x86_64.rpm php-gd-5.1.6-3.el4s1.9.x86_64.rpm php-imap-5.1.6-3.el4s1.9.x86_64.rpm php-ldap-5.1.6-3.el4s1.9.x86_64.rpm php-mbstring-5.1.6-3.el4s1.9.x86_64.rpm php-mysql-5.1.6-3.el4s1.9.x86_64.rpm php-ncurses-5.1.6-3.el4s1.9.x86_64.rpm php-odbc-5.1.6-3.el4s1.9.x86_64.rpm php-pdo-5.1.6-3.el4s1.9.x86_64.rpm php-pgsql-5.1.6-3.el4s1.9.x86_64.rpm php-snmp-5.1.6-3.el4s1.9.x86_64.rpm php-soap-5.1.6-3.el4s1.9.x86_64.rpm php-xml-5.1.6-3.el4s1.9.x86_64.rpm php-xmlrpc-5.1.6-3.el4s1.9.x86_64.rpm postgresql-jdbc-8.1.412-1jpp.el4s1.1.x86_64.rpm postgresql-jdbc-debuginfo-8.1.412-1jpp.el4s1.1.x86_64.rpm postgresqlclient7-7.4.19-1.el4s1.1.i386.rpm postgresqlclient7-7.4.19-1.el4s1.1.x86_64.rpm postgresqlclient7-debuginfo-7.4.19-1.el4s1.1.i386.rpm postgresqlclient7-debuginfo-7.4.19-1.el4s1.1.x86_64.rpm unixODBC-2.2.12-6.el4s1.1.i386.rpm unixODBC-2.2.12-6.el4s1.1.x86_64.rpm unixODBC-debuginfo-2.2.12-6.el4s1.1.i386.rpm unixODBC-debuginfo-2.2.12-6.el4s1.1.x86_64.rpm unixODBC-devel-2.2.12-6.el4s1.1.x86_64.rpm unixODBC-kde-2.2.12-6.el4s1.1.i386.rpm unixODBC-kde-2.2.12-6.el4s1.1.x86_64.rpm Red Hat Application Stack v1 for Enterprise Linux ES(v.4): Source: i386: httpd-2.0.63-2.el4s1.2.i386.rpm httpd-debuginfo-2.0.63-2.el4s1.2.i386.rpm httpd-devel-2.0.63-2.el4s1.2.i386.rpm httpd-manual-2.0.63-2.el4s1.2.i386.rpm mod_jk-ap20-1.2.26-1.el4s1.1.i386.rpm mod_jk-debuginfo-1.2.26-1.el4s1.1.i386.rpm mod_jk-manual-1.2.26-1.el4s1.1.i386.rpm mod_ssl-2.0.63-2.el4s1.2.i386.rpm mysql-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-bench-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-cluster-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-connector-odbc-3.51.24r1071-1.el4s1.1.i386.rpm mysql-connector-odbc-debuginfo-3.51.24r1071-1.el4s1.1.i386.rpm mysql-debuginfo-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-devel-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-libs-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-server-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-test-5.0.50sp1a-2.el4s1.1.i386.rpm perl-DBD-MySQL-4.006-1.el4.i386.rpm perl-DBD-MySQL-debuginfo-4.006-1.el4.i386.rpm perl-DBI-1.604-1.el4s1.i386.rpm perl-DBI-debuginfo-1.604-1.el4s1.i386.rpm php-5.1.6-3.el4s1.9.i386.rpm php-bcmath-5.1.6-3.el4s1.9.i386.rpm php-cli-5.1.6-3.el4s1.9.i386.rpm php-common-5.1.6-3.el4s1.9.i386.rpm php-dba-5.1.6-3.el4s1.9.i386.rpm php-debuginfo-5.1.6-3.el4s1.9.i386.rpm php-devel-5.1.6-3.el4s1.9.i386.rpm php-gd-5.1.6-3.el4s1.9.i386.rpm php-imap-5.1.6-3.el4s1.9.i386.rpm php-ldap-5.1.6-3.el4s1.9.i386.rpm php-mbstring-5.1.6-3.el4s1.9.i386.rpm php-mysql-5.1.6-3.el4s1.9.i386.rpm php-ncurses-5.1.6-3.el4s1.9.i386.rpm php-odbc-5.1.6-3.el4s1.9.i386.rpm php-pdo-5.1.6-3.el4s1.9.i386.rpm php-pgsql-5.1.6-3.el4s1.9.i386.rpm php-snmp-5.1.6-3.el4s1.9.i386.rpm php-soap-5.1.6-3.el4s1.9.i386.rpm php-xml-5.1.6-3.el4s1.9.i386.rpm php-xmlrpc-5.1.6-3.el4s1.9.i386.rpm postgresql-jdbc-8.1.412-1jpp.el4s1.1.i386.rpm postgresql-jdbc-debuginfo-8.1.412-1jpp.el4s1.1.i386.rpm postgresqlclient7-7.4.19-1.el4s1.1.i386.rpm postgresqlclient7-debuginfo-7.4.19-1.el4s1.1.i386.rpm unixODBC-2.2.12-6.el4s1.1.i386.rpm unixODBC-debuginfo-2.2.12-6.el4s1.1.i386.rpm unixODBC-devel-2.2.12-6.el4s1.1.i386.rpm unixODBC-kde-2.2.12-6.el4s1.1.i386.rpm x86_64: httpd-2.0.63-2.el4s1.2.x86_64.rpm httpd-debuginfo-2.0.63-2.el4s1.2.x86_64.rpm httpd-devel-2.0.63-2.el4s1.2.x86_64.rpm httpd-manual-2.0.63-2.el4s1.2.x86_64.rpm mod_jk-ap20-1.2.26-1.el4s1.1.x86_64.rpm mod_jk-debuginfo-1.2.26-1.el4s1.1.x86_64.rpm mod_jk-manual-1.2.26-1.el4s1.1.x86_64.rpm mod_ssl-2.0.63-2.el4s1.2.x86_64.rpm mysql-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-bench-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-cluster-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-connector-odbc-3.51.24r1071-1.el4s1.1.x86_64.rpm mysql-connector-odbc-debuginfo-3.51.24r1071-1.el4s1.1.x86_64.rpm mysql-debuginfo-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-debuginfo-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-devel-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-libs-5.0.50sp1a-2.el4s1.1.i386.rpm mysql-libs-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-server-5.0.50sp1a-2.el4s1.1.x86_64.rpm mysql-test-5.0.50sp1a-2.el4s1.1.x86_64.rpm perl-DBD-MySQL-4.006-1.el4.x86_64.rpm perl-DBD-MySQL-debuginfo-4.006-1.el4.x86_64.rpm perl-DBI-1.604-1.el4s1.x86_64.rpm perl-DBI-debuginfo-1.604-1.el4s1.x86_64.rpm php-5.1.6-3.el4s1.9.x86_64.rpm php-bcmath-5.1.6-3.el4s1.9.x86_64.rpm php-cli-5.1.6-3.el4s1.9.x86_64.rpm php-common-5.1.6-3.el4s1.9.x86_64.rpm php-dba-5.1.6-3.el4s1.9.x86_64.rpm php-debuginfo-5.1.6-3.el4s1.9.x86_64.rpm php-devel-5.1.6-3.el4s1.9.x86_64.rpm php-gd-5.1.6-3.el4s1.9.x86_64.rpm php-imap-5.1.6-3.el4s1.9.x86_64.rpm php-ldap-5.1.6-3.el4s1.9.x86_64.rpm php-mbstring-5.1.6-3.el4s1.9.x86_64.rpm php-mysql-5.1.6-3.el4s1.9.x86_64.rpm php-ncurses-5.1.6-3.el4s1.9.x86_64.rpm php-odbc-5.1.6-3.el4s1.9.x86_64.rpm php-pdo-5.1.6-3.el4s1.9.x86_64.rpm php-pgsql-5.1.6-3.el4s1.9.x86_64.rpm php-snmp-5.1.6-3.el4s1.9.x86_64.rpm php-soap-5.1.6-3.el4s1.9.x86_64.rpm php-xml-5.1.6-3.el4s1.9.x86_64.rpm php-xmlrpc-5.1.6-3.el4s1.9.x86_64.rpm postgresql-jdbc-8.1.412-1jpp.el4s1.1.x86_64.rpm postgresql-jdbc-debuginfo-8.1.412-1jpp.el4s1.1.x86_64.rpm postgresqlclient7-7.4.19-1.el4s1.1.i386.rpm postgresqlclient7-7.4.19-1.el4s1.1.x86_64.rpm postgresqlclient7-debuginfo-7.4.19-1.el4s1.1.i386.rpm postgresqlclient7-debuginfo-7.4.19-1.el4s1.1.x86_64.rpm unixODBC-2.2.12-6.el4s1.1.i386.rpm unixODBC-2.2.12-6.el4s1.1.x86_64.rpm unixODBC-debuginfo-2.2.12-6.el4s1.1.i386.rpm unixODBC-debuginfo-2.2.12-6.el4s1.1.x86_64.rpm unixODBC-devel-2.2.12-6.el4s1.1.x86_64.rpm unixODBC-kde-2.2.12-6.el4s1.1.i386.rpm unixODBC-kde-2.2.12-6.el4s1.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2008-2079 https://docs.redhat.com/en/ https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2008 Red Hat, Inc. . Important upgrade for Red Hat Software Suite v1.3, tackling vulnerabilities and providing improvements. Take action now!. Red Hat Update, MySQL Security, Application Stack Security, Privilege Escalation. . LinuxSecurity.com Team

Calendar 2 Jul 02, 2008 Red Hat
98

Red Hat: RHSA-2008:0505-01 Moderate: PHP And MySQL Security Fixes

Red Hat Application Stack v2.1 is now available. This update fixes various security issues and adds several enhancements. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Application Stack v2.1 security and enhancement update Advisory ID: RHSA-2008:0505-01 Product: Red Hat Application Stack Advisory URL: https://access.redhat.com/errata/RHSA-2008:0505.html Issue date: 2008-07-02 CVE Names: CVE-2008-2079 CVE-2008-2051 CVE-2007-5898 CVE-2007-5899 CVE-2007-4782 CVE-2008-2107 CVE-2008-2108 CVE-2008-0599 ==================================================================== 1. Summary: Red Hat Application Stack v2.1 is now available. This update fixes various security issues and adds several enhancements. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Application Stack v2 for Enterprise Linux (v.5) - i386, noarch, x86_64 3. Description: The Red Hat Application Stack is an integrated open source application stack, and includes JBoss Enterprise Application Platform (EAP). Starting with this update, JBoss EAP is no longer provided via the Application Stack channels. Instead, all Application Stack customers are automatically entitled to the JBoss EAP channels. This ensures all users have immediate access to JBoss EAP packages when they are released, ensuring lesser wait for security and critical patches. As a result, you must MANUALLY subscribe to the appropriate JBoss EAP channel, as all further JBoss EAP updates will only go to that channel. This update also entitles all customers to the JBoss EAP 4.3.0 channels. Users receive support for JBoss EAP 4.3.0 if they choose to install it. Important:downgrading from JBoss EAP 4.3.0 to 4.2.0 is unsupported. PHP was updated to version 5.2.6, fixing the following security issues: It was discovered that the PHP escapeshellcmd() function did not properly escape multi-byte characters which are not valid in the locale used by the script. This could allow an attacker to bypass quoting restrictions imposed by escapeshellcmd() and execute arbitrary commands if the PHP script was using certain locales. Scripts using the default UTF-8 locale are not affected by this issue. (CVE-2008-2051) The PHP functions htmlentities() and htmlspecialchars() did not properly recognize partial multi-byte sequences. Certain sequences of bytes could be passed through these functions without being correctly HTML-escaped. Depending on the browser being used, an attacker could use this flaw to conduct cross-site scripting attacks. (CVE-2007-5898) A PHP script which used the transparent session ID configuration option, or which used the output_add_rewrite_var() function, could leak session identifiers to external web sites. If a page included an HTML form with an ACTION attribute referencing a non-local URL, the user's session ID would be included in the form data passed to that URL. (CVE-2007-5899) It was discovered that the PHP fnmatch() function did not restrict the length of the string argument. An attacker could use this flaw to crash the PHP interpreter where a script used fnmatch() on untrusted input data. (CVE-2007-4782) It was discovered that PHP did not properly seed its pseudo-random number generator used by functions such as rand() and mt_rand(), possibly allowing an attacker to easily predict the generated pseudo-random values. (CVE-2008-2107, CVE-2008-2108) A flaw was found in PHP's CGI server API. If the web server did not set DOCUMENT_ROOT environment variable for PHP (e.g. when running PHP in the FastCGI server mode), an attacker could cause a crash of the PHP child process, causing a temporary denial of service.(CVE-2008-0599) MySQL was updated to version 5.0.50sp1a, fixing the following security issue: MySQL did not correctly check directories used as arguments for the DATA DIRECTORY and INDEX DIRECTORY directives. Using this flaw, an authenticated attacker could elevate their access privileges to tables created by other database users. Note: this attack does not work on existing tables. An attacker can only elevate their access to another user's tables as the tables are created. As well, the names of these created tables need to be predicted correctly for this attack to succeed. (CVE-2008-2079) The following packages are updated: * httpd to 2.2.8 * mod_jk to 1.2.26 * mod_perl to 2.0.4 * the MySQL Connector/ODBC to 3.51.24r1071 * the MySQL Connector/J (JDBC driver) to 5.0.8 * perl-DBD-MySQL to 4.006 * perl-DBI to 1.604 * postgresql to 8.2.7 * postgresql-jdbc to 8.2.508 * postgresqlclient81 to 8.1.11 * postgresql-odbc to 8.02.0500 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 285881 - CVE-2007-4782 php crash in glob() and fnmatch() functions 382411 - CVE-2007-5898 php htmlentities/htmlspecialchars multibyte sequences 382431 - CVE-2007-5899 php session ID leakage 445003 - CVE-2008-0599 php: buffer overflow in a CGI path translation 445006 - CVE-2008-2051 PHP multibyte shell escape flaw 445222 - CVE-2008-2079 mysql: privilege escalation via DATA/INDEX DIRECTORY directives 445684 - CVE-2008-2107 PHP 32 bit weak random seed 445685 - CVE-2008-2108 PHP weak 64 bit random seed 6. Package List: Red Hat Application Stack v2 for Enterprise Linux(v.5): Source: i386: httpd-2.2.8-1.el5s2.i386.rpm httpd-debuginfo-2.2.8-1.el5s2.i386.rpm httpd-devel-2.2.8-1.el5s2.i386.rpm httpd-manual-2.2.8-1.el5s2.i386.rpm mod_jk-ap20-1.2.26-1.el5s2.i386.rpm mod_jk-debuginfo-1.2.26-1.el5s2.i386.rpm mod_perl-2.0.4-3.el5s2.i386.rpm mod_perl-debuginfo-2.0.4-3.el5s2.i386.rpm mod_perl-devel-2.0.4-3.el5s2.i386.rpm mod_ssl-2.2.8-1.el5s2.i386.rpm mysql-5.0.50sp1a-2.el5s2.i386.rpm mysql-bench-5.0.50sp1a-2.el5s2.i386.rpm mysql-cluster-5.0.50sp1a-2.el5s2.i386.rpm mysql-connector-odbc-3.51.24r1071-1.el5s2.i386.rpm mysql-connector-odbc-debuginfo-3.51.24r1071-1.el5s2.i386.rpm mysql-debuginfo-5.0.50sp1a-2.el5s2.i386.rpm mysql-devel-5.0.50sp1a-2.el5s2.i386.rpm mysql-libs-5.0.50sp1a-2.el5s2.i386.rpm mysql-server-5.0.50sp1a-2.el5s2.i386.rpm mysql-test-5.0.50sp1a-2.el5s2.i386.rpm perl-DBD-MySQL-4.006-1.el5s2.i386.rpm perl-DBD-MySQL-debuginfo-4.006-1.el5s2.i386.rpm perl-DBI-1.604-1.el5s2.i386.rpm perl-DBI-debuginfo-1.604-1.el5s2.i386.rpm php-5.2.6-2.el5s2.i386.rpm php-bcmath-5.2.6-2.el5s2.i386.rpm php-cli-5.2.6-2.el5s2.i386.rpm php-common-5.2.6-2.el5s2.i386.rpm php-dba-5.2.6-2.el5s2.i386.rpm php-debuginfo-5.2.6-2.el5s2.i386.rpm php-devel-5.2.6-2.el5s2.i386.rpm php-gd-5.2.6-2.el5s2.i386.rpm php-imap-5.2.6-2.el5s2.i386.rpm php-ldap-5.2.6-2.el5s2.i386.rpm php-mbstring-5.2.6-2.el5s2.i386.rpm php-mysql-5.2.6-2.el5s2.i386.rpm php-ncurses-5.2.6-2.el5s2.i386.rpm php-odbc-5.2.6-2.el5s2.i386.rpm php-pdo-5.2.6-2.el5s2.i386.rpm php-pgsql-5.2.6-2.el5s2.i386.rpm php-snmp-5.2.6-2.el5s2.i386.rpm php-soap-5.2.6-2.el5s2.i386.rpm php-xml-5.2.6-2.el5s2.i386.rpm php-xmlrpc-5.2.6-2.el5s2.i386.rpm postgresql-8.2.9-1.el5s2.i386.rpm postgresql-contrib-8.2.9-1.el5s2.i386.rpm postgresql-debuginfo-8.2.9-1.el5s2.i386.rpm postgresql-devel-8.2.9-1.el5s2.i386.rpm postgresql-docs-8.2.9-1.el5s2.i386.rpm postgresql-jdbc-8.2.508-1jpp.el5s2.i386.rpm postgresql-jdbc-debuginfo-8.2.508-1jpp.el5s2.i386.rpm postgresql-libs-8.2.9-1.el5s2.i386.rpm postgresql-odbc-08.02.0500-1.el5s2.i386.rpm postgresql-odbc-debuginfo-08.02.0500-1.el5s2.i386.rpm postgresql-plperl-8.2.9-1.el5s2.i386.rpm postgresql-plpython-8.2.9-1.el5s2.i386.rpm postgresql-pltcl-8.2.9-1.el5s2.i386.rpm postgresql-python-8.2.9-1.el5s2.i386.rpm postgresql-server-8.2.9-1.el5s2.i386.rpm postgresql-tcl-8.2.9-1.el5s2.i386.rpm postgresql-test-8.2.9-1.el5s2.i386.rpm postgresqlclient81-8.1.11-1.el5s2.i386.rpm postgresqlclient81-debuginfo-8.1.11-1.el5s2.i386.rpm unixODBC-2.2.12-8.el5s2.i386.rpm unixODBC-debuginfo-2.2.12-8.el5s2.i386.rpm unixODBC-devel-2.2.12-8.el5s2.i386.rpm unixODBC-kde-2.2.12-8.el5s2.i386.rpm noarch: mysql-jdbc-5.0.8-1jpp.1.el5s2.noarch.rpm x86_64: httpd-2.2.8-1.el5s2.x86_64.rpm httpd-debuginfo-2.2.8-1.el5s2.x86_64.rpm httpd-devel-2.2.8-1.el5s2.x86_64.rpm httpd-manual-2.2.8-1.el5s2.x86_64.rpm mod_jk-ap20-1.2.26-1.el5s2.x86_64.rpm mod_jk-debuginfo-1.2.26-1.el5s2.x86_64.rpm mod_perl-2.0.4-3.el5s2.x86_64.rpm mod_perl-debuginfo-2.0.4-3.el5s2.x86_64.rpm mod_perl-devel-2.0.4-3.el5s2.x86_64.rpm mod_ssl-2.2.8-1.el5s2.x86_64.rpm mysql-5.0.50sp1a-2.el5s2.x86_64.rpm mysql-bench-5.0.50sp1a-2.el5s2.x86_64.rpm mysql-cluster-5.0.50sp1a-2.el5s2.x86_64.rpm mysql-connector-odbc-3.51.24r1071-1.el5s2.x86_64.rpm mysql-connector-odbc-debuginfo-3.51.24r1071-1.el5s2.x86_64.rpm mysql-debuginfo-5.0.50sp1a-2.el5s2.x86_64.rpm mysql-devel-5.0.50sp1a-2.el5s2.x86_64.rpm mysql-libs-5.0.50sp1a-2.el5s2.x86_64.rpm mysql-server-5.0.50sp1a-2.el5s2.x86_64.rpm mysql-test-5.0.50sp1a-2.el5s2.x86_64.rpm perl-DBD-MySQL-4.006-1.el5s2.x86_64.rpm perl-DBD-MySQL-debuginfo-4.006-1.el5s2.x86_64.rpm perl-DBI-1.604-1.el5s2.x86_64.rpm perl-DBI-debuginfo-1.604-1.el5s2.x86_64.rpm php-5.2.6-2.el5s2.x86_64.rpm php-bcmath-5.2.6-2.el5s2.x86_64.rpm php-cli-5.2.6-2.el5s2.x86_64.rpm php-common-5.2.6-2.el5s2.x86_64.rpm php-dba-5.2.6-2.el5s2.x86_64.rpm php-debuginfo-5.2.6-2.el5s2.x86_64.rpm php-devel-5.2.6-2.el5s2.x86_64.rpm php-gd-5.2.6-2.el5s2.x86_64.rpm php-imap-5.2.6-2.el5s2.x86_64.rpm php-ldap-5.2.6-2.el5s2.x86_64.rpm php-mbstring-5.2.6-2.el5s2.x86_64.rpm php-mysql-5.2.6-2.el5s2.x86_64.rpm php-ncurses-5.2.6-2.el5s2.x86_64.rpm php-odbc-5.2.6-2.el5s2.x86_64.rpm php-pdo-5.2.6-2.el5s2.x86_64.rpm php-pgsql-5.2.6-2.el5s2.x86_64.rpm php-snmp-5.2.6-2.el5s2.x86_64.rpm php-soap-5.2.6-2.el5s2.x86_64.rpm php-xml-5.2.6-2.el5s2.x86_64.rpm php-xmlrpc-5.2.6-2.el5s2.x86_64.rpm postgresql-8.2.9-1.el5s2.x86_64.rpm postgresql-contrib-8.2.9-1.el5s2.x86_64.rpm postgresql-debuginfo-8.2.9-1.el5s2.x86_64.rpm postgresql-devel-8.2.9-1.el5s2.x86_64.rpm postgresql-docs-8.2.9-1.el5s2.x86_64.rpm postgresql-jdbc-8.2.508-1jpp.el5s2.x86_64.rpm postgresql-jdbc-debuginfo-8.2.508-1jpp.el5s2.x86_64.rpm postgresql-libs-8.2.9-1.el5s2.x86_64.rpm postgresql-odbc-08.02.0500-1.el5s2.x86_64.rpm postgresql-odbc-debuginfo-08.02.0500-1.el5s2.x86_64.rpm postgresql-plperl-8.2.9-1.el5s2.x86_64.rpm postgresql-plpython-8.2.9-1.el5s2.x86_64.rpm postgresql-pltcl-8.2.9-1.el5s2.x86_64.rpm postgresql-python-8.2.9-1.el5s2.x86_64.rpm postgresql-server-8.2.9-1.el5s2.x86_64.rpm postgresql-tcl-8.2.9-1.el5s2.x86_64.rpm postgresql-test-8.2.9-1.el5s2.x86_64.rpm postgresqlclient81-8.1.11-1.el5s2.x86_64.rpm postgresqlclient81-debuginfo-8.1.11-1.el5s2.x86_64.rpm unixODBC-2.2.12-8.el5s2.x86_64.rpm unixODBC-debuginfo-2.2.12-8.el5s2.x86_64.rpm unixODBC-devel-2.2.12-8.el5s2.x86_64.rpm unixODBC-kde-2.2.12-8.el5s2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7.References: https://www.cve.org/CVERecord?id=CVE-2008-2079 https://www.cve.org/CVERecord?id=CVE-2008-2051 https://www.cve.org/CVERecord?id=CVE-2007-5898 https://www.cve.org/CVERecord?id=CVE-2007-5899 https://www.cve.org/CVERecord?id=CVE-2007-4782 https://www.cve.org/CVERecord?id=CVE-2008-2107 https://www.cve.org/CVERecord?id=CVE-2008-2108 https://www.cve.org/CVERecord?id=CVE-2008-0599 https://docs.redhat.com/en/ https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2008 Red Hat, Inc. . The release of Red Hat Application Stack version 2.1 introduces various security improvements and fixes, evaluated as moderate risk by the Red Hat Security Team.. Red Hat Application Stack, PHP Security Updates, MySQL Fixes. . LinuxSecurity.com Team

Calendar 2 Jul 02, 2008 Red Hat
98

Red Hat Application Stack v1 Moderate: Perl Memory Allocation Risk

Updated Perl packages that fix security issues for Red Hat Application Stack v1.2 are now available. A flaw was found in Perl's regular expression engine. Specially crafted input to a regular expression can cause Perl to improperly allocate memory, possibly resulting in arbitrary code running with the permissions of the user running Perl. This update has been rated as having important security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Important: perl security update Advisory ID: RHSA-2007:1011-01 Advisory URL: https://access.redhat.com/errata/RHSA-2007:1011.html Issue date: 2007-11-05 Updated on: 2007-11-05 Product: Red Hat Application Stack CVE Names: CVE-2007-5116 - ---------------------------------------------------------------------1. Summary: Updated Perl packages that fix security issues for Red Hat Application Stack v1.2 are now available. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Application Stack v1 for Enterprise Linux AS (v.4) - i386, x86_64 Red Hat Application Stack v1 for Enterprise Linux ES (v.4) - i386, x86_64 3. Problem description: Perl is a high-level programming language commonly used for system administration utilities and Web programming. A flaw was found in Perl's regular expression engine. Specially crafted input to a regular expression can cause Perl to improperly allocate memory, possibly resulting in arbitrary code running with the permissions of the user running Perl. (CVE-2007-5116) Users of Perl are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. Red Hat would like to thank Tavis Ormandy and Will Drewry for properly disclosing this issue. 4. Solution: Before applying this update, makesure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bug IDs fixed (http://bugzilla.redhat.com/): 323571 - CVE-2007-5116 perl regular expression UTF parsing errors 6. RPMs required: Red Hat Application Stack v1 for Enterprise Linux AS (v.4): SRPMS: 73b5b047e89da16e563da600fb1f27bb perl-5.8.8-5.el4s1_2.src.rpm i386: 594456f0c0a07778426f2db35dc6d83c perl-5.8.8-5.el4s1_2.i386.rpm cf0e2c42cc134c75c932d8bfae8b7ac0 perl-debuginfo-5.8.8-5.el4s1_2.i386.rpm c412d4db3a2d6b963115b811e2a3fe7a perl-suidperl-5.8.8-5.el4s1_2.i386.rpm x86_64: 24c17031ef19b328c25517a5e89e3766 perl-5.8.8-5.el4s1_2.x86_64.rpm 2038481ca705701df16082bc989e3279 perl-debuginfo-5.8.8-5.el4s1_2.x86_64.rpm 523b0a11d061ae2a51a13f09620e0c64 perl-suidperl-5.8.8-5.el4s1_2.x86_64.rpm Red Hat Application Stack v1 for Enterprise Linux ES (v.4): SRPMS: 73b5b047e89da16e563da600fb1f27bb perl-5.8.8-5.el4s1_2.src.rpm i386: 594456f0c0a07778426f2db35dc6d83c perl-5.8.8-5.el4s1_2.i386.rpm cf0e2c42cc134c75c932d8bfae8b7ac0 perl-debuginfo-5.8.8-5.el4s1_2.i386.rpm c412d4db3a2d6b963115b811e2a3fe7a perl-suidperl-5.8.8-5.el4s1_2.i386.rpm x86_64: 24c17031ef19b328c25517a5e89e3766 perl-5.8.8-5.el4s1_2.x86_64.rpm 2038481ca705701df16082bc989e3279 perl-debuginfo-5.8.8-5.el4s1_2.x86_64.rpm 523b0a11d061ae2a51a13f09620e0c64 perl-suidperl-5.8.8-5.el4s1_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2007-5116 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2007 Red Hat, Inc. . Essential Perlsecurity patches for Red Hat Application Stack version 1.2 have been released to mitigate vulnerabilities related to memory handling and associated threats.. Perl Security, Red Hat Updates, Application Stack Security, Memory Allocation Issue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 05, 2007 Important Red Hat
98

Red Hat: RHSA-2023:1234-01 Moderate: PHP Security Update

Updated PHP packages that fix several security issues are now available for Red Hat Application Stack. This update has been rated as having moderate security impact by the Red Hat Security Response Team. . - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: php security update Advisory ID: RHSA-2007:0917-01 Advisory URL: https://access.redhat.com/errata/RHSA-2007:0917.html Issue date: 2007-10-23 Updated on: 2007-10-23 Product: Red Hat Application Stack CVE Names: CVE-2007-3799 CVE-2007-3996 CVE-2007-3998 CVE-2007-4659 CVE-2007-4658 CVE-2007-4670 CVE-2007-4661 - ---------------------------------------------------------------------1. Summary: Updated PHP packages that fix several security issues are now available for Red Hat Application Stack. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Application Stack v2 for Enterprise Linux (v.5) - i386, x86_64 3. Problem description: PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Web server. These updated packages address the following vulnerabilities: Various integer overflow flaws were found in the PHP gd extension. A script that could be forced to resize images from an untrusted source could possibly allow a remote attacker to execute arbitrary code as the apache user. (CVE-2007-3996) A previous security update introduced a bug into PHP session cookie handling. This could allow an attacker to stop a victim from viewing a vulnerable web site if the victim has first visited a malicious web page under the control of the attacker, and that page can set a cookie for the vulnerable web site. (CVE-2007-4670) A flaw was found in the PHP money_format function. If a remote attacker was able to pass arbitrary data tothe money_format function this could possibly result in an information leak or denial of service. Note that is is unusual for a PHP script to pass user-supplied data to the money_format function. (CVE-2007-4658) A flaw was found in the PHP wordwrap function. If a remote attacker was able to pass arbitrary data to the wordwrap function this could possibly result in a denial of service. (CVE-2007-3998) A bug was found in PHP session cookie handling. This could allow an attacker to create a cross-site cookie insertion attack if a victim follows an untrusted carefully-crafted URL. (CVE-2007-3799) A flaw was found in handling of dynamic changes to global variables. A script which used certain functions which change global variables could be forced to enable the register_globals configuration option, possibly resulting in global variable injection. (CVE-2007-4659) An integer overflow flaw was found in the PHP chunk_split function. If a remote attacker was able to pass arbitrary data to the third argument of chunk_split they could possibly execute arbitrary code as the apache user. Note that it is unusual for a PHP script to use the chunk_split function with a user-supplied third argument. (CVE-2007-4661) Users of PHP should upgrade to these updated packages which contain backported patches to correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red HatNetwork, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed (http://bugzilla.redhat.com/): 250726 - CVE-2007-3799 php cross-site cookie insertion 276081 - CVE-2007-3998 php floating point exception inside wordwrap 276531 - CVE-2007-4659 php zend_alter_ini_entry() memory_limit interruption 278011 - CVE-2007-4658 php money_format format string issue 278031 - CVE-2007-3996 php multiple integer overflows in gd 278041 - CVE-2007-4670 php malformed cookie handling 278161 - CVE-2007-4661 php size calculation in chunk_split 6. RPMs required: Red Hat Application Stack v2 for Enterprise Linux (v.5) : SRPMS: e687175bc07eab174e25abfa0dca9534 php-5.2.3-3.el5s2.src.rpm i386: b75257f1461ddacc4225dfbd891b87c0 php-5.2.3-3.el5s2.i386.rpm cb472d5aaf4ead14957de0623bb3d4b0 php-bcmath-5.2.3-3.el5s2.i386.rpm 4699cbe6cdbc71a5f6a1759978f54251 php-cli-5.2.3-3.el5s2.i386.rpm 4724204a1e88eb1c5aed999dbf91ec67 php-common-5.2.3-3.el5s2.i386.rpm b9de6d61bfeac292c42f942fa9028ab0 php-dba-5.2.3-3.el5s2.i386.rpm 846597bc34fe474947aa7b53ccb5c9da php-debuginfo-5.2.3-3.el5s2.i386.rpm aabc9ea6aab27c1ee72a2f572b2a7d6e php-devel-5.2.3-3.el5s2.i386.rpm 8f80b518067d270abebebad0ae106ad3 php-gd-5.2.3-3.el5s2.i386.rpm 2a94e6d5702a43e7ce122700d10623df php-imap-5.2.3-3.el5s2.i386.rpm 9be1e1f1586fbed06b072fe1450f87a1 php-ldap-5.2.3-3.el5s2.i386.rpm 6022524a6d83957557931e40b2e7b0eb php-mbstring-5.2.3-3.el5s2.i386.rpm bdc5fdbeed9c3ec4a38d39f5c311a380 php-mysql-5.2.3-3.el5s2.i386.rpm 766c6870d011afdef2252b38586b8757 php-ncurses-5.2.3-3.el5s2.i386.rpm f485a913c5a2a62ecfab4af6ebdfeeb6 php-odbc-5.2.3-3.el5s2.i386.rpm 4accbad7b61afde3cf04e7080816ab27 php-pdo-5.2.3-3.el5s2.i386.rpm 948e9ded764717a015b13545f8c3ae76 php-pgsql-5.2.3-3.el5s2.i386.rpm 58d564da90e8cb502f5f275b306dbb40 php-snmp-5.2.3-3.el5s2.i386.rpm 3f4c98ff0f1e6bb6d82f095210b717d3 php-soap-5.2.3-3.el5s2.i386.rpm 8948939da05b4c3fba26361de13a8fba php-xml-5.2.3-3.el5s2.i386.rpm 112adcbe4b0d4d678b3e31b3283ac3cb php-xmlrpc-5.2.3-3.el5s2.i386.rpm x86_64: 1abd82cd077414578c0e9d089aad86a1 php-5.2.3-3.el5s2.x86_64.rpm f0ee0e1049ddf2468d2660de416e99f8 php-bcmath-5.2.3-3.el5s2.x86_64.rpm fed55d2cd7a05ef9a713a3dca80b7854 php-cli-5.2.3-3.el5s2.x86_64.rpm 0fe6dedad39ec7c72f365c73cea751be php-common-5.2.3-3.el5s2.x86_64.rpm 0fafd4f847edd0e46395883faf26158c php-dba-5.2.3-3.el5s2.x86_64.rpm 7e7de482ff435455ea95d8fcbd2b2433 php-debuginfo-5.2.3-3.el5s2.x86_64.rpm d9bb222938344fde246415f30b6707a4 php-devel-5.2.3-3.el5s2.x86_64.rpm e43176b50da43f3c03667cd839d40892 php-gd-5.2.3-3.el5s2.x86_64.rpm bcae5919312d5c7667aebd8c37f73def php-imap-5.2.3-3.el5s2.x86_64.rpm c46e4cff3b9d4951d99689d8b8e66450 php-ldap-5.2.3-3.el5s2.x86_64.rpm 1e7610c3e9f7980ed5746ad9d1617fa2 php-mbstring-5.2.3-3.el5s2.x86_64.rpm 9742d3a1435fd94b9546d9ec14e825ee php-mysql-5.2.3-3.el5s2.x86_64.rpm 19333f47eaae706437e09de493e8dc1a php-ncurses-5.2.3-3.el5s2.x86_64.rpm f320e99dd5c77c7c72cc675be50ad66f php-odbc-5.2.3-3.el5s2.x86_64.rpm 71081a91ab2a7479ebde113726316452 php-pdo-5.2.3-3.el5s2.x86_64.rpm f03c434be520b19dff2717e35a773038 php-pgsql-5.2.3-3.el5s2.x86_64.rpm 542e220bce399a52527e10bbc0266c9a php-snmp-5.2.3-3.el5s2.x86_64.rpm 2e093e544a9daab2d8d47949a98ecf12 php-soap-5.2.3-3.el5s2.x86_64.rpm 9dd382af22a630f7e9d8522c451713ad php-xml-5.2.3-3.el5s2.x86_64.rpm e5606dab1ed2af4baa68ddd3ba6fdfcb php-xmlrpc-5.2.3-3.el5s2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7.References: https://www.cve.org/CVERecord?id=CVE-2007-3799 https://www.cve.org/CVERecord?id=CVE-2007-3996 https://www.cve.org/CVERecord?id=CVE-2007-3998 https://www.cve.org/CVERecord?id=CVE-2007-4659 https://www.cve.org/CVERecord?id=CVE-2007-4658 https://www.cve.org/CVERecord?id=CVE-2007-4670 https://www.cve.org/CVERecord?id=CVE-2007-4661 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2007 Red Hat, Inc. . Ubuntu releases an important software patch for Python tackling various vulnerabilities. Keep your system safe by applying the latest updates.. Red Hat PHP Patch, Application Stack Security, Moderate Security Fix. . LinuxSecurity.com Team

Calendar 2 Oct 23, 2007 Red Hat
98

Red Hat Application Stack RHSA-2007:0396-02 Low: mod_perl DoS Issue

Updated mod_perl packages that fix a security issue are now available for Red Hat Application Stack. An issue was found in the "namespace_from_uri" method of the ModPerl::RegistryCooker class. If a server implemented a mod_perl registry module using this method, a remote attacker requesting a carefully crafted URI can cause resource consumption, which could lead to a denial of service This update has been rated as having low security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Low: mod_perl security update Advisory ID: RHSA-2007:0396-02 Advisory URL: https://access.redhat.com/errata/RHSA-2007:0396.html Issue date: 2007-06-20 Updated on: 2007-06-20 Product: Red Hat Application Stack CVE Names: CVE-2007-1349 - ---------------------------------------------------------------------1. Summary: Updated mod_perl packages that fix a security issue are now available for Red Hat Application Stack. This update has been rated as having low security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Application Stack v1 for Enterprise Linux AS (v.4) - i386, x86_64 Red Hat Application Stack v1 for Enterprise Linux ES (v.4) - i386, x86_64 3. Problem description: Mod_perl incorporates a Perl interpreter into the Apache web server, so that the Apache web server can directly execute Perl code. An issue was found in the "namespace_from_uri" method of the ModPerl::RegistryCooker class. If a server implemented a mod_perl registry module using this method, a remote attacker requesting a carefully crafted URI can cause resource consumption, which could lead to a denial of service (CVE-2007-1349). Users of mod_perl should update to these erratum packages which contain a backported fix to correct this issue. 4. Solution: Before applying this update, make sure thatall previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bug IDs fixed (http://bugzilla.redhat.com/): 240423 - CVE-2007-1349 mod_perl PerlRun denial of service 6. RPMs required: Red Hat Application Stack v1 for Enterprise Linux AS (v.4): SRPMS: 71ce8c451f23f952b398a60613d27452 mod_perl-2.0.3-1.el4s1.3.src.rpm i386: 071559439ac99e4e890b188b7bc3af34 mod_perl-2.0.3-1.el4s1.3.i386.rpm 01a1c66651d67919cfaed482354e9baa mod_perl-debuginfo-2.0.3-1.el4s1.3.i386.rpm 55b67c6346ce43bf7d06379fc5ec1341 mod_perl-devel-2.0.3-1.el4s1.3.i386.rpm x86_64: 376a4d9530a5efcd9341abaca2ee9fef mod_perl-2.0.3-1.el4s1.3.x86_64.rpm b04f7455c08e335141fb8116c4db7a75 mod_perl-debuginfo-2.0.3-1.el4s1.3.x86_64.rpm eb4b8b127d93beb3214a59b4de25f251 mod_perl-devel-2.0.3-1.el4s1.3.x86_64.rpm Red Hat Application Stack v1 for Enterprise Linux ES (v.4): SRPMS: 71ce8c451f23f952b398a60613d27452 mod_perl-2.0.3-1.el4s1.3.src.rpm i386: 071559439ac99e4e890b188b7bc3af34 mod_perl-2.0.3-1.el4s1.3.i386.rpm 01a1c66651d67919cfaed482354e9baa mod_perl-debuginfo-2.0.3-1.el4s1.3.i386.rpm 55b67c6346ce43bf7d06379fc5ec1341 mod_perl-devel-2.0.3-1.el4s1.3.i386.rpm x86_64: 376a4d9530a5efcd9341abaca2ee9fef mod_perl-2.0.3-1.el4s1.3.x86_64.rpm b04f7455c08e335141fb8116c4db7a75 mod_perl-debuginfo-2.0.3-1.el4s1.3.x86_64.rpm eb4b8b127d93beb3214a59b4de25f251 mod_perl-devel-2.0.3-1.el4s1.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2007-1349 https://access.redhat.com/security/updates/classification#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2007 Red Hat, Inc. . Recent mod_perl updates issued by Red Hat resolve a minor security vulnerability linked to potential service interruptions. Discover more details.. mod_perl update, red hat security, denial of service mitigation, application stack security. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Jun 29, 2007 Low Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here