php4 4:4.4.0-3ubuntu1 source package in Ubuntu

Changelog

php4 (4:4.4.0-3ubuntu1) breezy-security; urgency=low


  * SECURITY UPDATE: multiple fixes backported from new upstream releases:
    - Resolves a local denial of service in the apache2 SAPI, which can
      be triggered by using session.save_path in .htaccess; CVE-2005-3319
    - Resolves an infinite loop in the exif_read_data function which can
      be triggered with a specially-crafted JPEG image; CVE-2005-3353
    - Resolves an XSS vulnerability in the phpinfo function; CVE-2005-3388
    - Resolves a vulnerability in the parse_str function whereby a remote
      attacker can fool PHP into turning on register_globals, thus making
      applications vulnerable to global variable injections; CVE-2005-3389
    - Resolves a vulnerability in the RFC1867 file upload feature where, if
      register_globals is enabled, a remote attacker can modify the GLOBALS
      array with a multipart/form-data POST request; see CVE-2005-3390
    - Resolves numerous safe_mode and open_basedir bypasses; CVE-2005-3391
    - Resolves INI settings leaks in the apache2 SAPI, leading to safe_mode
      and open_basedir bypasses between virtual hosts; CVE-2005-3392
    - Resolves a CRLF injection vulnerability in the mb_send_mail function,
      allowing injection of arbitrary mail headers; see CVE-2005-3883

 -- Adam Conrad <email address hidden>  Mon, 19 Dec 2005 16:48:53 +1100

Upload details

Uploaded by:
Ubuntu Archive Auto-Sync
Uploaded to:
Breezy
Original maintainer:
Debian PHP Maintainers
Architectures:
any
Section:
web
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
php4_4.4.0-3ubuntu1.dsc 1.7 KiB deb95fb3f42ab3ee271da7a948017a5ef7d42c5e7af68581ab13050b4f377f88
php4_4.4.0.orig.tar.gz 4.7 MiB 5f52a15b5f1dd53283e6ad6234d3f61a49f413192a2b3a51c61669634c99cc76
php4_4.4.0-3ubuntu1.diff.gz 100.1 KiB c7336d4063bb8e3de675f01313b37fb58c2e6ec622c60667bcca59e195781e52

No changes file available.

Binary packages built by this source

libapache-mod-php4: No summary available for libapache-mod-php4 in ubuntu breezy.

No description available for libapache-mod-php4 in ubuntu breezy.

libapache2-mod-php4: No summary available for libapache2-mod-php4 in ubuntu breezy.

No description available for libapache2-mod-php4 in ubuntu breezy.

php4: No summary available for php4 in ubuntu breezy.

No description available for php4 in ubuntu breezy.

php4-cgi: No summary available for php4-cgi in ubuntu breezy.

No description available for php4-cgi in ubuntu breezy.

php4-cli: No summary available for php4-cli in ubuntu breezy.

No description available for php4-cli in ubuntu breezy.

php4-common: No summary available for php4-common in ubuntu breezy.

No description available for php4-common in ubuntu breezy.

php4-curl: No summary available for php4-curl in ubuntu breezy.

No description available for php4-curl in ubuntu breezy.

php4-dev: No summary available for php4-dev in ubuntu breezy.

No description available for php4-dev in ubuntu breezy.

php4-domxml: No summary available for php4-domxml in ubuntu breezy.

No description available for php4-domxml in ubuntu breezy.

php4-gd: No summary available for php4-gd in ubuntu breezy.

No description available for php4-gd in ubuntu breezy.

php4-ldap: No summary available for php4-ldap in ubuntu breezy.

No description available for php4-ldap in ubuntu breezy.

php4-mcal: No summary available for php4-mcal in ubuntu breezy.

No description available for php4-mcal in ubuntu breezy.

php4-mhash: No summary available for php4-mhash in ubuntu breezy.

No description available for php4-mhash in ubuntu breezy.

php4-mysql: No summary available for php4-mysql in ubuntu breezy.

No description available for php4-mysql in ubuntu breezy.

php4-odbc: No summary available for php4-odbc in ubuntu breezy.

No description available for php4-odbc in ubuntu breezy.

php4-pear: No summary available for php4-pear in ubuntu breezy.

No description available for php4-pear in ubuntu breezy.

php4-pgsql: No summary available for php4-pgsql in ubuntu breezy.

No description available for php4-pgsql in ubuntu breezy.

php4-recode: No summary available for php4-recode in ubuntu breezy.

No description available for php4-recode in ubuntu breezy.

php4-snmp: No summary available for php4-snmp in ubuntu breezy.

No description available for php4-snmp in ubuntu breezy.

php4-sybase: No summary available for php4-sybase in ubuntu breezy.

No description available for php4-sybase in ubuntu breezy.

php4-xslt: No summary available for php4-xslt in ubuntu breezy.

No description available for php4-xslt in ubuntu breezy.