Ispravljeno je više sigurnosnih ranjivosti programskog paketa PHP, distribuiranog s operacijskim sustavom Fedora 15. PHP je skriptni programski jezik koji se koristi za razvoj dinamičkih web stranica. Propusti su vezani uz cjelobrojno prepisivanje (eng. integer overflow) u "ext/shmop/shmop.c", pogrešnu obradu podataka u "exif.c", itd. Udaljenom napadaču omogućuju napad uskraćivanjem usluga (eng. Denial of Service), čitanje povjerljivih podataka iz memorije te izvršavanje proizvoljnog programskog koda. Svim korisnicima navedenog programskog paketa preporuča se njegova nadogradnja u svrhu zaštite sigurnosti.
Fedora Update Notification
2011-03-19 05:35:10
Name : php
Product : Fedora 15
Version : 5.3.6
Release : 1.fc15
Summary : PHP scripting language for creating dynamic web sites
Description :
PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated web pages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts.
The php package contains the module which adds support for the PHP
language to Apache HTTP Server.
Update Information:
Security Enhancements and Fixes in PHP 5.3.6:
* Enforce security in the fastcgi protocol parsing with fpm SAPI.
* Fixed bug #54247 (format-string vulnerability on Phar). (CVE-2011-1153)
* Fixed bug #54193 (Integer overflow in shmop_read()). (CVE-2011-1092)
* Fixed bug #54055 (buffer overrun with high values for precision ini
* Fixed bug #54002 (crash on crafted tag in exif). (CVE-2011-0708)
* Fixed bug #53885 (ZipArchive segfault with FL_UNCHANGED on empty archive).
Full upstream changelog :
[ 1 ] Bug #688378 - CVE-2011-1153 php: several format string vulnerabilities
in PHP's Phar extension
[ 2 ] Bug #680972 - CVE-2011-0708 php: buffer over-read in Exif extension
[ 3 ] Bug #688735 - CVE-2011-0421 php/libzip: segfault with FL_UNCHANGED on
empty archive in zip_name_locate()
This update can be installed with the "yum" update program. Use
su -c 'yum update php' at the command line.
For more information, refer to "Managing Software with yum",
available at
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke