SCIENTIFIC-LINUX-ERRATA Archives

July 2008

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Wed, 16 Jul 2008 13:31:26 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (82 lines)
Synopsis:	Moderate: php security and bug fix update
Issue date:	2008-07-16
CVE Names:	CVE-2008-2051 CVE-2007-5898 CVE-2007-5899
                 CVE-2007-4782 CVE-2008-2107 CVE-2008-2108

It was discovered that the PHP escapeshellcmd() function did not properly
escape multi-byte characters which are not valid in the locale used by the
script. This could allow an attacker to bypass quoting restrictions imposed
by escapeshellcmd() and execute arbitrary commands if the PHP script was
using certain locales. Scripts using the default UTF-8 locale are not
affected by this issue. (CVE-2008-2051)

The PHP functions htmlentities() and htmlspecialchars() did not properly
recognize partial multi-byte sequences. Certain sequences of bytes could be
passed through these functions without being correctly HTML-escaped.
Depending on the browser being used, an attacker could use this flaw to
conduct cross-site scripting attacks. (CVE-2007-5898)

A PHP script which used the transparent session ID configuration option, or
which used the output_add_rewrite_var() function, could leak session
identifiers to external web sites. If a page included an HTML form with an
ACTION attribute referencing a non-local URL, the user's session ID would
be included in the form data passed to that URL. (CVE-2007-5899)

It was discovered that the PHP fnmatch() function did not restrict the
length of the string argument. An attacker could use this flaw to crash the
PHP interpreter where a script used fnmatch() on untrusted input data.
(CVE-2007-4782)

It was discovered that PHP did not properly seed its pseudo-random number
generator used by functions such as rand() and mt_rand(), possibly allowing
an attacker to easily predict the generated pseudo-random values.
(CVE-2008-2107, CVE-2008-2108)

As well, these updated packages fix the following bug:

* after 2008-01-01, when using PEAR version 1.3.6 or older, it was not
possible to use the PHP Extension and Application Repository (PEAR) to
upgrade or install packages. In these updated packages, PEAR has been
upgraded to version 1.4.9, which restores support for the current
pear.php.net update server. The following changes were made to the PEAR
packages included in php-pear: Console_Getopt and Archive_Tar are now
included by default, and XML_RPC has been upgraded to version 1.5.0.

SL 4.x

    SRPMS:
php-4.3.9-3.22.12.src.rpm
    i386:
php-4.3.9-3.22.12.i386.rpm
php-devel-4.3.9-3.22.12.i386.rpm
php-domxml-4.3.9-3.22.12.i386.rpm
php-gd-4.3.9-3.22.12.i386.rpm
php-imap-4.3.9-3.22.12.i386.rpm
php-ldap-4.3.9-3.22.12.i386.rpm
php-mbstring-4.3.9-3.22.12.i386.rpm
php-mysql-4.3.9-3.22.12.i386.rpm
php-ncurses-4.3.9-3.22.12.i386.rpm
php-odbc-4.3.9-3.22.12.i386.rpm
php-pear-4.3.9-3.22.12.i386.rpm
php-pgsql-4.3.9-3.22.12.i386.rpm
php-snmp-4.3.9-3.22.12.i386.rpm
php-xmlrpc-4.3.9-3.22.12.i386.rpm
    x86_64:
php-4.3.9-3.22.12.x86_64.rpm
php-devel-4.3.9-3.22.12.x86_64.rpm
php-domxml-4.3.9-3.22.12.x86_64.rpm
php-gd-4.3.9-3.22.12.x86_64.rpm
php-imap-4.3.9-3.22.12.x86_64.rpm
php-ldap-4.3.9-3.22.12.x86_64.rpm
php-mbstring-4.3.9-3.22.12.x86_64.rpm
php-mysql-4.3.9-3.22.12.x86_64.rpm
php-ncurses-4.3.9-3.22.12.x86_64.rpm
php-odbc-4.3.9-3.22.12.x86_64.rpm
php-pear-4.3.9-3.22.12.x86_64.rpm
php-pgsql-4.3.9-3.22.12.x86_64.rpm
php-snmp-4.3.9-3.22.12.x86_64.rpm
php-xmlrpc-4.3.9-3.22.12.x86_64.rpm

-Connie Sieh
-Troy Dawson

ATOM RSS1 RSS2