Re: Multiple Vulnerabilities in PHP fileupload

From: Peter Pentchev (roam@ringlet.net)
Date: 02/28/02


Date: Thu, 28 Feb 2002 17:35:13 +0200
From: Peter Pentchev <roam@ringlet.net>
To: Oliver Rompcik <rompcik@informatik.uni-bonn.de>


On Thu, Feb 28, 2002 at 03:55:49PM +0100, Oliver Rompcik wrote:
> CERT reported several vulnerabilities in all PHP Versions <= 4.1.1.
> See advisory at http://www.cert.org/advisories/CA-2002-05.html
>
> Fixed version of PHP 4.1.2 is available at http://www.php.net.
> Until fixed FreeBSD binary package is available, users should build 4.1.2
> from source.

..or from the www/mod_php port, which was updated to include a fix for
this vulnerability 17 hours ago, at Wed Feb 27 22:17:22 2002 UTC.

G'luck,
Peter

-- 
Peter Pentchev	roam@ringlet.net	roam@FreeBSD.org
PGP key:	http://people.FreeBSD.org/~roam/roam.key.asc
Key fingerprint	FDBA FD79 C26F 3C51 C95E  DF9E ED18 B68D 1619 4553
When you are not looking at it, this sentence is in Spanish.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • RE: php pack() security update
    ... I'm waiting for redhat to release updates for php on as3. ... SECUNIA ADVISORY ID: ... Multiple vulnerabilities have been reported in PHP, ... Successful exploitation requires that PHP runs on a multi-threaded ...
    (RedHat)
  • php pack() security update
    ... I'm waiting for redhat to release updates for php on as3. ... SECUNIA ADVISORY ID: ... Multiple vulnerabilities have been reported in PHP, ... Successful exploitation requires that PHP runs on a multi-threaded ...
    (RedHat)
  • Multiple Vulnerabilities in PHP fileupload
    ... CERT reported several vulnerabilities in all PHP Versions <= 4.1.1. ... See advisory at http://www.cert.org/advisories/CA-2002-05.html ... Until fixed FreeBSD binary package is available, ...
    (FreeBSD-Security)
  • [NEWS] Vulnerability Issues in Implementations of the H.323 Protocol (Generic)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... discovered a number of implementation specific vulnerabilities in the ... The severity of these vulnerabilities varies by vendor. ...
    (Securiteam)
  • iDEFENSE Security Advisory 03.31.05: PHP getimagesize() Multiple Denial of Service Vulnerabilities
    ... PHP getimagesize() Multiple Denial of Service Vulnerabilities ... iDEFENSE has confirmed the existence of these vulnerabilities in PHP ...
    (Bugtraq)