Säkerhetsbulletin från Debian
DSA-1206-1 php4 -- flera sårbarheter
- Rapporterat den:
- 2006-11-06
- Berörda paket:
- php4
- Sårbara:
- Ja
- Referenser i säkerhetsdatabaser:
- I Mitres CVE-förteckning: CVE-2005-3353, CVE-2006-3017, CVE-2006-4482, CVE-2006-5465.
- Ytterligare information:
-
Flera utifrån nåbara sårbarheter har upptäckts i PHP, ett HTML-inbyggt skriptspråk för serversidan, vilket kan leda till exekvering av godtycklig kod. Projektet Common Vulnerabilities and Exposures identifierar följande problem:
- CVE-2005-3353
Tim Starling upptäckte att saknas städning av indata i EXIF-modulen kunde användas till en överbelastningsattack.
- CVE-2006-3017
Stefan Esser upptäckte ett säkerhetskritiskt programmeringsfel i hashtabellimplementationen i den interna Zend-motorn.
- CVE-2006-4482
Det upptäcktes att funktionerna str_repeat() och wordwrap() inte utför tillräckliga buffertlängdskontroller på 64-bitarssystem, vilket kunde leda till exekvering av godtycklig kod.
- CVE-2006-5465
Stefan Esser upptäckte ett buffertspill i funktionerna htmlspecialchars() och htmlentities(), vilket möjligen kunde leda till exekvering av godtycklig kod.
För den stabila utgåvan (Sarge) har dessa problem rättats i version 4:4.3.10-18. Byggen för hppa och m68k kommer tillhandahållas senare så fort de är tillgängliga.
För den instabila utgåvan (Sid) har dessa problem rättats i version 4:4.4.4-4 av php4 och version 5.1.6-6 av php5.
Vi rekommenderar att ni uppgraderar era php4-paket.
- CVE-2005-3353
- Rättat i:
-
Debian GNU/Linux 3.1 (sarge)
- Källkod:
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-18.dsc
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-18.diff.gz
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10.orig.tar.gz
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-18.diff.gz
- Arkitekturoberoende komponent:
- http://security.debian.org/pool/updates/main/p/php4/php4-pear_4.3.10-18_all.deb
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-18_all.deb
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-18_all.deb
- Alpha:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_alpha.deb
- AMD64:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_amd64.deb
- ARM:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_ia64.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_sparc.deb
MD5-kontrollsummor för dessa filer finns i originalbulletinen.