GLSA: php

From: Daniel Ahlberg (aliz@gentoo.org)
Date: 11/20/02

  • Next message: Daniel Ahlberg: "GLSA: samba"
    From: Daniel Ahlberg <aliz@gentoo.org>
    Date: Wed, 20 Nov 2002 14:16:30 +0100
    To: bugtraq@securityfocus.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - - --------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200211-005
    - - --------------------------------------------------------------------

    PACKAGE : php & mod_php
    SUMMARY : buffer overflow
    DATE    : 2002-11-20 13:11 UTC
    EXPLOIT : local & remote

    - - --------------------------------------------------------------------

    - From advisory:

    Two vulnerabilities exists in mail() PHP function. The first one
    allows to execute any program/script bypassing safe_mode restriction,
    the second one may give an open-relay script if mail() function is not
    carefully used in PHP scripts.

    Read the full advisory at
    http://marc.theaimsgroup.com/?l=bugtraq&m=103011916928204&w=2 recommended that all Gentoo Linux users who are running

    SOLUTION

    It is recommended that all Gentoo Linux users who are running
    dev-php/php-4.2.2-r1 and/or dev-php/mod_php-4.2.2-r1 and earlier
    update their systems as follows:

    emerge rsync
    emerge php
      and/or
    emerge mod_php
    emerge clean

    - - --------------------------------------------------------------------
    aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
    rphillips@gentoo.org
    - - --------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.7 (GNU/Linux)

    iD8DBQE924srfT7nyhUpoZMRAj4XAJ9YugJ+Gvb0+dQbmUJIFPbJJMFEgACgtPNQ
    OXAlpSYMVp0CcExWEK2ZQlI=
    =kuEw
    -----END PGP SIGNATURE-----



    Relevant Pages

    • [Full-Disclosure] GLSA: netscape-flash (200303-9)
      ... GENTOO LINUX SECURITY ANNOUNCEMENT 200303-9 ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge netscape-flash ...
      (Full-Disclosure)
    • [Full-Disclosure] GLSA: man (200303-13)
      ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge sync ...
      (Full-Disclosure)
    • [Full-Disclosure] GLSA: php
      ... GENTOO LINUX SECURITY ANNOUNCEMENT 200211-005 ... Two vulnerabilities exists in mailPHP function. ... Read the full advisory at ... emerge rsync ...
      (Full-Disclosure)
    • GLSA: rxvt (200303-16)
      ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge sync ...
      (Bugtraq)
    • GLSA: eterm (200303-1)
      ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge -u eterm ...
      (Bugtraq)