php5 5.1.2-1ubuntu3.19 source package in Ubuntu

Changelog

php5 (5.1.2-1ubuntu3.19) dapper-security; urgency=low

  * SECURITY UPDATE: denial of service via xmlrpc crafted argument
    - debian/patches/CVE-2010-0397.patch: make sure method_name isn't empty
      in ext/xmlrpc/xmlrpc-epi-php.c, add test to
      ext/xmlrpc/tests/bug51288.phpt.
    - CVE-2010-0397
  * SECURITY UPDATE: weak entropy in Linear Congruential Generator (LCG)
    - debian/patches/CVE-2010-1128.patch: add more entropy in
      ext/standard/lcg.c.
    - CVE-2010-1128
  * SECURITY UPDATE: safe_mode bypass via trailing slash in dir pathnames
    - debian/patches/CVE-2010-1129.patch: properly validate pathname in
      ext/standard/file.c.
    - CVE-2010-1129
  * SECURITY UPDATE: arbitrary code execution via empty SQL query
    - debian/patches/CVE-2010-1868.patch: use ecalloc instead of emalloc in
      ext/sqlite/sqlite.c.
    - CVE-2010-1868
  * SECURITY UPDATE: denial of service via fnmatch stack consumption
    - debian/patches/CVE-2010-1917.patch: limit size of pattern in
      ext/standard/file.c.
    - CVE-2010-1917
  * SECURITY UPDATE: sensitive information disclosure via error messages
    - debian/patches/CVE-2010-2531.patch: don't display data when flushing
      output buffer in ext/standard/{var.c,php_var.h}.
    - CVE-2010-2531
  * SECURITY UPDATE: arbitrary session variable modification via crafted
    session variable name
    - debian/patches/CVE-2010-3065.patch: handle PS_UNDEF_MARKER marker in
      ext/session/session.c.
    - CVE-2010-3065
 -- Marc Deslauriers <email address hidden>   Thu, 16 Sep 2010 10:24:44 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Dapper
Original maintainer:
Debian PHP Maintainers
Architectures:
any
Section:
web
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
php5_5.1.2.orig.tar.gz 7.7 MiB cafedfc92b80cba342abfeab91a6498b080dc3af8c22667423c33a3cec956251
php5_5.1.2-1ubuntu3.19.diff.gz 151.1 KiB 49842248cd0a0e8898f82ebabdb3677b5bb17ab74ed09834f013692f3122b5db
php5_5.1.2-1ubuntu3.19.dsc 1.7 KiB 63d8c634d5a82a28e22737f78eec02c7e5cf4cebe647c7801cde0de8b11796fe

View changes file

Binary packages built by this source

libapache2-mod-php5: No summary available for libapache2-mod-php5 in ubuntu dapper.

No description available for libapache2-mod-php5 in ubuntu dapper.

php-pear: No summary available for php-pear in ubuntu dapper.

No description available for php-pear in ubuntu dapper.

php5: No summary available for php5 in ubuntu dapper.

No description available for php5 in ubuntu dapper.

php5-cgi: No summary available for php5-cgi in ubuntu dapper.

No description available for php5-cgi in ubuntu dapper.

php5-cli: No summary available for php5-cli in ubuntu dapper.

No description available for php5-cli in ubuntu dapper.

php5-common: No summary available for php5-common in ubuntu dapper.

No description available for php5-common in ubuntu dapper.

php5-curl: No summary available for php5-curl in ubuntu dapper.

No description available for php5-curl in ubuntu dapper.

php5-dev: No summary available for php5-dev in ubuntu dapper.

No description available for php5-dev in ubuntu dapper.

php5-gd: No summary available for php5-gd in ubuntu dapper.

No description available for php5-gd in ubuntu dapper.

php5-ldap: No summary available for php5-ldap in ubuntu dapper.

No description available for php5-ldap in ubuntu dapper.

php5-mhash: No summary available for php5-mhash in ubuntu dapper.

No description available for php5-mhash in ubuntu dapper.

php5-mysql: No summary available for php5-mysql in ubuntu dapper.

No description available for php5-mysql in ubuntu dapper.

php5-mysqli: No summary available for php5-mysqli in ubuntu dapper.

No description available for php5-mysqli in ubuntu dapper.

php5-odbc: No summary available for php5-odbc in ubuntu dapper.

No description available for php5-odbc in ubuntu dapper.

php5-pgsql: No summary available for php5-pgsql in ubuntu dapper.

No description available for php5-pgsql in ubuntu dapper.

php5-recode: No summary available for php5-recode in ubuntu dapper.

No description available for php5-recode in ubuntu dapper.

php5-snmp: No summary available for php5-snmp in ubuntu dapper.

No description available for php5-snmp in ubuntu dapper.

php5-sqlite: No summary available for php5-sqlite in ubuntu dapper.

No description available for php5-sqlite in ubuntu dapper.

php5-sybase: No summary available for php5-sybase in ubuntu dapper.

No description available for php5-sybase in ubuntu dapper.

php5-xmlrpc: No summary available for php5-xmlrpc in ubuntu dapper.

No description available for php5-xmlrpc in ubuntu dapper.

php5-xsl: No summary available for php5-xsl in ubuntu dapper.

No description available for php5-xsl in ubuntu dapper.