php5 5.1.2-1ubuntu3.5 source package in Ubuntu
Changelog
php5 (5.1.2-1ubuntu3.5) dapper-security; urgency=low * SECURITY UPDATE: Remote code execution. * Add debian/patches/CVE-2007-0906_imap.patch: - Buffer overflows in the imap extension. - http://cvs.php.net/viewvc.cgi/php-src/ext/imap/php_imap.c?r1=1.208.2.7.2.11&r2=1.208.2.7.2.12 - http://cvs.php.net/viewvc.cgi/php-src/ext/imap/php_imap.c?r1=1.208.2.7.2.15&r2=1.208.2.7.2.16 * Add debian/patches/CVE-2007-0906_session.patch: - Buffer overflow in the session extension. - http://cvs.php.net/viewvc.cgi/php-src/ext/session/session.c?r1=1.417.2.8.2.22&r2=1.417.2.8.2.23 * Add debian/patches/CVE-2007-0906_streams.patch: - Buffer overflows in the stream filters functions. - http://cvs.php.net/viewvc.cgi/php-src/ext/standard/streamsfuncs.c?r1=1.58.2.6.2.12&r2=1.58.2.6.2.13 - http://cvs.php.net/viewvc.cgi/php-src/ext/standard/streamsfuncs.c?r1=1.98&r2=1.99 * Add debian/patches/CVE-2007-0906_string.patch: - Buffer overflow in the string extension. - http://cvs.php.net/viewvc.cgi/php-src/ext/standard/string.c?r1=1.629&r2=1.631 * Add debian/patches/CVE-2007-0907.patch: - Buffer underflow in sapi_header_op() that can be exploited to crash the PHP interpreter. - http://cvs.php.net/viewvc.cgi/php-src/main/SAPI.c?r1=1.202.2.7.2.3&r2=1.202.2.7.2.4 * Add debian/patches/CVE-2007-0908.patch: - Fix forgotten initialization of key_length and buffer overflow in the wddx extension that could be exploited to reveal memory that is not supposed to be accessible (potential information disclosure). - http://cvs.php.net/viewvc.cgi/php-src/ext/wddx/wddx.c?r1=1.119.2.10.2.8&r2=1.119.2.10.2.10 * Add debian/patches/CVE-2007-0909_print.patch: - Fix format string vulnerability on 64 bit systems in the *print() functions. - http://cvs.php.net/viewvc.cgi/php-src/ext/standard/formatted_print.c?r1=1.82.2.1.2.11&r2=1.82.2.1.2.12 * Add debian/patches/CVE-2007-0909_odbc.patch: - Fix format string vulnerability on 64 bit systems in odbc_result_all(). - http://cvs.php.net/viewvc.cgi/php-src/ext/odbc/php_odbc.c?r1=1.189.2.4.2.1&r2=1.189.2.4.2.2 - http://cvs.php.net/viewvc.cgi/php-src/ext/odbc/php_odbc.c?r1=1.189.2.4.2.3&r2=1.189.2.4.2.4 * Add debian/patches/CVE-2007-0910.patch: - Fix clobbering of superglobal variables during session variable unserialization. - http://cvs.php.net/viewvc.cgi/php-src/ext/session/session.c?r1=1.458&r2=1.459 - http://cvs.php.net/viewvc.cgi/php-src/ext/session/session.c?r1=1.417.2.8.2.24&r2=1.417.2.8.2.26 - http://cvs.php.net/viewvc.cgi/php-src/main/php_variables.c?r1=1.104.2.10.2.3&r2=1.104.2.10.2.4 * Add debian/patches/CVE-2007-0988.patch: - Fix infinite loop in zend_hash_init() when unserializing untrusted data on 64 bit systems. - http://cvs.php.net/viewvc.cgi/ZendEngine2/zend_hash.c?r1=1.121.2.4.2.5&r2=1.121.2.4.2.6 -- Martin Pitt <email address hidden> Wed, 21 Feb 2007 09:25:41 +0100
Upload details
- Uploaded by:
- Martin Pitt
- Uploaded to:
- Dapper
- Original maintainer:
- Debian PHP Maintainers
- Architectures:
- any
- Section:
- web
- Urgency:
- Low Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
php5_5.1.2.orig.tar.gz | 7.7 MiB | cafedfc92b80cba342abfeab91a6498b080dc3af8c22667423c33a3cec956251 |
php5_5.1.2-1ubuntu3.5.diff.gz | 110.5 KiB | 4837c205cf774a3857260da614a683d0562bf5e633791811be83eaab41ef8a2f |
php5_5.1.2-1ubuntu3.5.dsc | 1.7 KiB | 585ac569953ed793021574bb689e41201f9ea392331c54d39a680d374865c1d0 |
Binary packages built by this source
- libapache2-mod-php5: No summary available for libapache2-mod-php5 in ubuntu dapper.
No description available for libapache2-mod-php5 in ubuntu dapper.
- php-pear: No summary available for php-pear in ubuntu dapper.
No description available for php-pear in ubuntu dapper.
- php5: No summary available for php5 in ubuntu dapper.
No description available for php5 in ubuntu dapper.
- php5-cgi: No summary available for php5-cgi in ubuntu dapper.
No description available for php5-cgi in ubuntu dapper.
- php5-cli: No summary available for php5-cli in ubuntu dapper.
No description available for php5-cli in ubuntu dapper.
- php5-common: No summary available for php5-common in ubuntu dapper.
No description available for php5-common in ubuntu dapper.
- php5-curl: No summary available for php5-curl in ubuntu dapper.
No description available for php5-curl in ubuntu dapper.
- php5-dev: No summary available for php5-dev in ubuntu dapper.
No description available for php5-dev in ubuntu dapper.
- php5-gd: No summary available for php5-gd in ubuntu dapper.
No description available for php5-gd in ubuntu dapper.
- php5-ldap: No summary available for php5-ldap in ubuntu dapper.
No description available for php5-ldap in ubuntu dapper.
- php5-mhash: No summary available for php5-mhash in ubuntu dapper.
No description available for php5-mhash in ubuntu dapper.
- php5-mysql: No summary available for php5-mysql in ubuntu dapper.
No description available for php5-mysql in ubuntu dapper.
- php5-mysqli: No summary available for php5-mysqli in ubuntu dapper.
No description available for php5-mysqli in ubuntu dapper.
- php5-odbc: No summary available for php5-odbc in ubuntu dapper.
No description available for php5-odbc in ubuntu dapper.
- php5-pgsql: No summary available for php5-pgsql in ubuntu dapper.
No description available for php5-pgsql in ubuntu dapper.
- php5-recode: No summary available for php5-recode in ubuntu dapper.
No description available for php5-recode in ubuntu dapper.
- php5-snmp: No summary available for php5-snmp in ubuntu dapper.
No description available for php5-snmp in ubuntu dapper.
- php5-sqlite: No summary available for php5-sqlite in ubuntu dapper.
No description available for php5-sqlite in ubuntu dapper.
- php5-sybase: No summary available for php5-sybase in ubuntu dapper.
No description available for php5-sybase in ubuntu dapper.
- php5-xmlrpc: No summary available for php5-xmlrpc in ubuntu dapper.
No description available for php5-xmlrpc in ubuntu dapper.
- php5-xsl: No summary available for php5-xsl in ubuntu dapper.
No description available for php5-xsl in ubuntu dapper.