U programskom paketu php otkriveno je nekoliko sigurnosnih ranjivosti koje se mogu iskoristiti udaljeno za izvođenje DoS napada, pokretanje proizvoljnog programskog koda, otkrivanje lozinki ili izmjenu proizvoljnih datoteka.
Neki od propusta su uzrokovani nepravilnom provjerom ulaznog imena datoteke u funkciji "rfc1867_post_handler" u datoteci "main/rfc1867.c", preljevom međuspremnika u funkciji "socket_connect" u datoteci "ext/sockets/sockets.c" te cjelobrojnim prepisivanjem u funkciji "SdnToJulian" u proširenju "Calendar".
Posljedica:
Svi propusti se mogu iskoristiti udaljeno, a moguće posljedice su: DoS napad, izvršavanje programskog koda, stvaranje i izmjena proizvoljnih datoteka ili otkrivanje lozinke.
Rješenje:
Kako bi se zaštitili, korisnicima se savjetuje primjena odgovarajućih programskih zakrpi.
CentOS Errata and Security Advisory 2011:1423 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2011-1423.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
223af9e4f04f1d42d3508ada752cdb02 php53-5.3.3-1.el5_7.3.i386.rpm
d925a7a20ea6f56cc5cc555dd4e24002 php53-bcmath-5.3.3-1.el5_7.3.i386.rpm
09d003a1bc50e31931c24aada21f8d2b php53-cli-5.3.3-1.el5_7.3.i386.rpm
9d851c175d18b67663dccceadb410ed5 php53-common-5.3.3-1.el5_7.3.i386.rpm
91e203e51bbaf64c5957dc942b3c2770 php53-dba-5.3.3-1.el5_7.3.i386.rpm
c095bc8f5f2f0ea7545d11180983b197 php53-devel-5.3.3-1.el5_7.3.i386.rpm
42fa169093034a237bb2ca300321a07d php53-gd-5.3.3-1.el5_7.3.i386.rpm
8ab1ece71e20942b91af4aa1d0442e6b php53-imap-5.3.3-1.el5_7.3.i386.rpm
d53e749d8668d34fc9ba8be571c1ca4c php53-intl-5.3.3-1.el5_7.3.i386.rpm
0d2bcc72fd7ec16517107c750c0dfd90 php53-ldap-5.3.3-1.el5_7.3.i386.rpm
23bc265b655eff64f8568897be9fb0f0 php53-mbstring-5.3.3-1.el5_7.3.i386.rpm
9c090d367b1f2241a6c80069026c7e90 php53-mysql-5.3.3-1.el5_7.3.i386.rpm
a64331e50a8f851eeeee1d5f7cb7254e php53-odbc-5.3.3-1.el5_7.3.i386.rpm
962c836f8ae8e2751c515e8aed7f1b12 php53-pdo-5.3.3-1.el5_7.3.i386.rpm
26f5c1da4763cb6c053710b540bdef61 php53-pgsql-5.3.3-1.el5_7.3.i386.rpm
3412e9ce0604fc737d4cab307e77ea3b php53-process-5.3.3-1.el5_7.3.i386.rpm
dbe446c4afb7fd56a1c821726eed857f php53-pspell-5.3.3-1.el5_7.3.i386.rpm
9aa33f6207cea07886a2e33e161e6c34 php53-snmp-5.3.3-1.el5_7.3.i386.rpm
42539efb05ae5e076d70c4101aaeb615 php53-soap-5.3.3-1.el5_7.3.i386.rpm
3d930dc70145d6925b4d7781ab31cbf6 php53-xml-5.3.3-1.el5_7.3.i386.rpm
f100b35c71e16d4c8551b8b8ae40cc96 php53-xmlrpc-5.3.3-1.el5_7.3.i386.rpm
Source:
bfa56ce9d335b242e3e733431872e410 php53-5.3.3-1.el5_7.3.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
CentOS Errata and Security Advisory 2011:1423 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2011-1423.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
dff715443179e84abd9b6a9ef0988f59 php53-5.3.3-1.el5_7.3.x86_64.rpm
17e7a8785e1b3029d2a08f69e425ae4b php53-bcmath-5.3.3-1.el5_7.3.x86_64.rpm
179db65bd52ae2d82906d039e5053abd php53-cli-5.3.3-1.el5_7.3.x86_64.rpm
eb399729eac65694a5c487ea428e4d5f php53-common-5.3.3-1.el5_7.3.x86_64.rpm
369a16b59333c56afde6e156221ca37d php53-dba-5.3.3-1.el5_7.3.x86_64.rpm
356c89306c65f72417318b0a6febac1c php53-devel-5.3.3-1.el5_7.3.x86_64.rpm
7c054405fcda999f0a56a348bcf5ed1f php53-gd-5.3.3-1.el5_7.3.x86_64.rpm
ca74baa225d8444cb36cdd547f12a1bb php53-imap-5.3.3-1.el5_7.3.x86_64.rpm
e1fbf1427c811fbfbe114c98e26ec156 php53-intl-5.3.3-1.el5_7.3.x86_64.rpm
75e11be23b839fcf4be2e3c4ba777878 php53-ldap-5.3.3-1.el5_7.3.x86_64.rpm
e96a80941ee28c644dbf4a140622cfc2 php53-mbstring-5.3.3-1.el5_7.3.x86_64.rpm
75d6a876c3d9fdc29084b11db83fa1ec php53-mysql-5.3.3-1.el5_7.3.x86_64.rpm
0574f227d4dc70c9c7706025d1306246 php53-odbc-5.3.3-1.el5_7.3.x86_64.rpm
ff3f668966e1353acc287447d172276d php53-pdo-5.3.3-1.el5_7.3.x86_64.rpm
f5ffefe48918e50e2cce8daa5c69a662 php53-pgsql-5.3.3-1.el5_7.3.x86_64.rpm
8e2b6b898aeafaa9af43d76fe7c3fd88 php53-process-5.3.3-1.el5_7.3.x86_64.rpm
6e41cf2e158514c524e63a35c3e95e0f php53-pspell-5.3.3-1.el5_7.3.x86_64.rpm
80b9470beeadd5c8a43237f122bfae88 php53-snmp-5.3.3-1.el5_7.3.x86_64.rpm
e4ae83e1542b655dada908c2bead662c php53-soap-5.3.3-1.el5_7.3.x86_64.rpm
638c42cc5f8221d818f69b4d9517391e php53-xml-5.3.3-1.el5_7.3.x86_64.rpm
5919dbe8390e66a5749a052fc25f66e4 php53-xmlrpc-5.3.3-1.el5_7.3.x86_64.rpm
Source:
bfa56ce9d335b242e3e733431872e410 php53-5.3.3-1.el5_7.3.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
Posljednje sigurnosne preporuke