SCIENTIFIC-LINUX-ERRATA Archives

December 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Wed, 11 Dec 2013 15:58:48 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (127 lines)
Synopsis:          Critical: php53 and php security update
Advisory ID:       SLSA-2013:1813-1
Issue Date:        2013-12-11
CVE Numbers:       CVE-2013-6420
--

A memory corruption flaw was found in the way the openssl_x509_parse()
function of the PHP openssl extension parsed X.509 certificates. A remote
attacker could use this flaw to provide a malicious self-signed
certificate or a certificate signed by a trusted authority to a PHP
application using the aforementioned function, causing the application to
crash or, possibly, allow the attacker to execute arbitrary code with the
privileges of the user running the PHP interpreter. (CVE-2013-6420)

After installing the updated packages, the httpd daemon must be restarted
for the update to take effect.
--

SL5
  x86_64
    php53-5.3.3-22.el5_10.x86_64.rpm
    php53-bcmath-5.3.3-22.el5_10.x86_64.rpm
    php53-cli-5.3.3-22.el5_10.x86_64.rpm
    php53-common-5.3.3-22.el5_10.x86_64.rpm
    php53-dba-5.3.3-22.el5_10.x86_64.rpm
    php53-debuginfo-5.3.3-22.el5_10.x86_64.rpm
    php53-devel-5.3.3-22.el5_10.x86_64.rpm
    php53-gd-5.3.3-22.el5_10.x86_64.rpm
    php53-imap-5.3.3-22.el5_10.x86_64.rpm
    php53-intl-5.3.3-22.el5_10.x86_64.rpm
    php53-ldap-5.3.3-22.el5_10.x86_64.rpm
    php53-mbstring-5.3.3-22.el5_10.x86_64.rpm
    php53-mysql-5.3.3-22.el5_10.x86_64.rpm
    php53-odbc-5.3.3-22.el5_10.x86_64.rpm
    php53-pdo-5.3.3-22.el5_10.x86_64.rpm
    php53-pgsql-5.3.3-22.el5_10.x86_64.rpm
    php53-process-5.3.3-22.el5_10.x86_64.rpm
    php53-pspell-5.3.3-22.el5_10.x86_64.rpm
    php53-snmp-5.3.3-22.el5_10.x86_64.rpm
    php53-soap-5.3.3-22.el5_10.x86_64.rpm
    php53-xml-5.3.3-22.el5_10.x86_64.rpm
    php53-xmlrpc-5.3.3-22.el5_10.x86_64.rpm
  i386
    php53-5.3.3-22.el5_10.i386.rpm
    php53-bcmath-5.3.3-22.el5_10.i386.rpm
    php53-cli-5.3.3-22.el5_10.i386.rpm
    php53-common-5.3.3-22.el5_10.i386.rpm
    php53-dba-5.3.3-22.el5_10.i386.rpm
    php53-debuginfo-5.3.3-22.el5_10.i386.rpm
    php53-devel-5.3.3-22.el5_10.i386.rpm
    php53-gd-5.3.3-22.el5_10.i386.rpm
    php53-imap-5.3.3-22.el5_10.i386.rpm
    php53-intl-5.3.3-22.el5_10.i386.rpm
    php53-ldap-5.3.3-22.el5_10.i386.rpm
    php53-mbstring-5.3.3-22.el5_10.i386.rpm
    php53-mysql-5.3.3-22.el5_10.i386.rpm
    php53-odbc-5.3.3-22.el5_10.i386.rpm
    php53-pdo-5.3.3-22.el5_10.i386.rpm
    php53-pgsql-5.3.3-22.el5_10.i386.rpm
    php53-process-5.3.3-22.el5_10.i386.rpm
    php53-pspell-5.3.3-22.el5_10.i386.rpm
    php53-snmp-5.3.3-22.el5_10.i386.rpm
    php53-soap-5.3.3-22.el5_10.i386.rpm
    php53-xml-5.3.3-22.el5_10.i386.rpm
    php53-xmlrpc-5.3.3-22.el5_10.i386.rpm
SL6
  x86_64
    php-5.3.3-27.el6_5.x86_64.rpm
    php-bcmath-5.3.3-27.el6_5.x86_64.rpm
    php-cli-5.3.3-27.el6_5.x86_64.rpm
    php-common-5.3.3-27.el6_5.x86_64.rpm
    php-dba-5.3.3-27.el6_5.x86_64.rpm
    php-debuginfo-5.3.3-27.el6_5.x86_64.rpm
    php-devel-5.3.3-27.el6_5.x86_64.rpm
    php-embedded-5.3.3-27.el6_5.x86_64.rpm
    php-enchant-5.3.3-27.el6_5.x86_64.rpm
    php-fpm-5.3.3-27.el6_5.x86_64.rpm
    php-gd-5.3.3-27.el6_5.x86_64.rpm
    php-imap-5.3.3-27.el6_5.x86_64.rpm
    php-intl-5.3.3-27.el6_5.x86_64.rpm
    php-ldap-5.3.3-27.el6_5.x86_64.rpm
    php-mbstring-5.3.3-27.el6_5.x86_64.rpm
    php-mysql-5.3.3-27.el6_5.x86_64.rpm
    php-odbc-5.3.3-27.el6_5.x86_64.rpm
    php-pdo-5.3.3-27.el6_5.x86_64.rpm
    php-pgsql-5.3.3-27.el6_5.x86_64.rpm
    php-process-5.3.3-27.el6_5.x86_64.rpm
    php-pspell-5.3.3-27.el6_5.x86_64.rpm
    php-recode-5.3.3-27.el6_5.x86_64.rpm
    php-snmp-5.3.3-27.el6_5.x86_64.rpm
    php-soap-5.3.3-27.el6_5.x86_64.rpm
    php-tidy-5.3.3-27.el6_5.x86_64.rpm
    php-xml-5.3.3-27.el6_5.x86_64.rpm
    php-xmlrpc-5.3.3-27.el6_5.x86_64.rpm
    php-zts-5.3.3-27.el6_5.x86_64.rpm
  i386
    php-5.3.3-27.el6_5.i686.rpm
    php-bcmath-5.3.3-27.el6_5.i686.rpm
    php-cli-5.3.3-27.el6_5.i686.rpm
    php-common-5.3.3-27.el6_5.i686.rpm
    php-dba-5.3.3-27.el6_5.i686.rpm
    php-debuginfo-5.3.3-27.el6_5.i686.rpm
    php-devel-5.3.3-27.el6_5.i686.rpm
    php-embedded-5.3.3-27.el6_5.i686.rpm
    php-enchant-5.3.3-27.el6_5.i686.rpm
    php-fpm-5.3.3-27.el6_5.i686.rpm
    php-gd-5.3.3-27.el6_5.i686.rpm
    php-imap-5.3.3-27.el6_5.i686.rpm
    php-intl-5.3.3-27.el6_5.i686.rpm
    php-ldap-5.3.3-27.el6_5.i686.rpm
    php-mbstring-5.3.3-27.el6_5.i686.rpm
    php-mysql-5.3.3-27.el6_5.i686.rpm
    php-odbc-5.3.3-27.el6_5.i686.rpm
    php-pdo-5.3.3-27.el6_5.i686.rpm
    php-pgsql-5.3.3-27.el6_5.i686.rpm
    php-process-5.3.3-27.el6_5.i686.rpm
    php-pspell-5.3.3-27.el6_5.i686.rpm
    php-recode-5.3.3-27.el6_5.i686.rpm
    php-snmp-5.3.3-27.el6_5.i686.rpm
    php-soap-5.3.3-27.el6_5.i686.rpm
    php-tidy-5.3.3-27.el6_5.i686.rpm
    php-xml-5.3.3-27.el6_5.i686.rpm
    php-xmlrpc-5.3.3-27.el6_5.i686.rpm
    php-zts-5.3.3-27.el6_5.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2