Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1647-1] New php5 packages fix several vulnerabilities (

    From Thijs Kinkhorst@1:229/2 to All on Tue Oct 7 09:00:16 2008
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1647-1 [email protected] http://www.debian.org/security/ Thijs Kinkhorst October 07, 2008 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : php5
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2008-3658 CVE-2008-3659 CVE-2008-3660
    Debian Bug : 499987 499988 499989

    Several vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language. The Common Vulnerabilities and
    Exposures project identifies the following problems:

    CVE-2008-3658

    Buffer overflow in the imageloadfont function allows a denial
    of service or code execution through a crafted font file.

    CVE-2008-3659

    Buffer overflow in the memnstr function allows a denial of
    service or code execution via a crafted delimiter parameter
    to the explode function.

    CVE-2008-3660

    Denial of service is possible in the FastCGI module by a
    remote attacker by making a request with multiple dots
    before the extension.

    For the stable distribution (etch), these problems have been fixed in
    version 5.2.0-8+etch13.

    For the testing (lenny) and unstable distribution (sid), these problems
    have been fixed in version 5.2.6-4.

    We recommend that you upgrade your php5 package.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/p/php5/php5_5.2.0.orig.tar.gz
    Size/MD5 checksum: 8583491 52d7e8b3d8d7573e75c97340f131f988
    http://security.debian.org/pool/updates/main/p/php5/php5_5.2.0-8+etch13.diff.gz
    Size/MD5 checksum: 121493 10f6d3ac9ecccb7373f40c0d99cdf43f
    http://security.debian.org/pool/updates/main/p/php5/php5_5.2.0-8+etch13.dsc
    Size/MD5 checksum: 1978 8ba966963b8c4b37ea56d0cef80e7039

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/p/php5/php-pear_5.2.0-8+etch13_all.deb
    Size/MD5 checksum: 312520 0073d8cd1e953316e18a1ebdf4131c13
    http://security.debian.org/pool/updates/main/p/php5/php5_5.2.0-8+etch13_all.deb
    Size/MD5 checksum: 1048 f2233a4fe8d7bf941738e152a9f59871

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/p/php5/php5-dev_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 345128 360a909a1ed151fe93001b20370b6d14
    http://security.debian.org/pool/updates/main/p/php5/php5-tidy_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 17532 5c43d788e0b376b0b181712705cc1980
    http://security.debian.org/pool/updates/main/p/php5/php5-mysql_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 70890 e91ef57210ab7b565a759673a5ed168f
    http://security.debian.org/pool/updates/main/p/php5/php5-xmlrpc_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 40284 f11151b96165ed8d0b4571fe3c25a828
    http://security.debian.org/pool/updates/main/p/php5/php5-cgi_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 4935658 3dfdde53682c0c171389703a97f16df1
    http://security.debian.org/pool/updates/main/p/php5/php5-xsl_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 13372 8b26e1d5862a981b2430aecbf72c492f
    http://security.debian.org/pool/updates/main/p/php5/php5-gd_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 36644 dbefd7ed6397e05df2c23e47e392b2e8
    http://security.debian.org/pool/updates/main/p/php5/php5-snmp_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 11830 a2ed568bfeb2f15e2c8c50c81d877dc3
    http://security.debian.org/pool/updates/main/p/php5/php5-sybase_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 19588 074a2dce0c9f56e0edff3c67b4cebb08
    http://security.debian.org/pool/updates/main/p/php5/php5-mcrypt_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 13462 2c1379aca13ce35e7a17bfda0c5d2392
    http://security.debian.org/pool/updates/main/p/php5/php5-common_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 220834 050fdd8f50774574a33a4ff6876c9eb8
    http://security.debian.org/pool/updates/main/p/php5/php5-mhash_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 5302 539d47ca751209e5d0e691b2dc99c7cb
    http://security.debian.org/pool/updates/main/p/php5/php5-pspell_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 9042 39ac2aa15828135c873e50b5793e5648
    http://security.debian.org/pool/updates/main/p/php5/libapache-mod-php5_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 2562250 f6290dd9eb8a6ad0a427d5fa3b2481e0
    http://security.debian.org/pool/updates/main/p/php5/php5-ldap_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 18600 e76355a0c54eaa3ffc13b0edae7c2f78
    http://security.debian.org/pool/updates/main/p/php5/php5-imap_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 36500 b7de2d6e801b25c74ab0541ec9560f2c
    http://security.debian.org/pool/updates/main/p/php5/php5-recode_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 4940 1131d46110c4be6a02986ff80ec43f2a
    http://security.debian.org/pool/updates/main/p/php5/php5-pgsql_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 55632 ef74d652f1c097d4781387d7d3e68b38
    http://security.debian.org/pool/updates/main/p/php5/php5-sqlite_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 38840 7134c697386c814599fd51121ec9ad7b
    http://security.debian.org/pool/updates/main/p/php5/php5-curl_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 24954 3f44b52eaa4d99d801af234914c63df2
    http://security.debian.org/pool/updates/main/p/php5/libapache2-mod-php5_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 2562500 daddb8d9cef21652e1294f2c870669b4
    http://security.debian.org/pool/updates/main/p/php5/php5-odbc_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 36062 79ce2b779f6bc6faa9a6551244bebc16
    http://security.debian.org/pool/updates/main/p/php5/php5-cli_5.2.0-8+etch13_alpha.deb
    Size/MD5 checksum: 2483910 7e528736241567d7431f646b465d0064

    amd64 architecture (AMD x86_64 (AMD64))


    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 42:07:09
    Calls: 12,109
    Files: 15,007
    Messages: 6,518,421

© >>> Magnum BBS <<<, 2026