php5 5.2.3-1ubuntu6.1 source package in Ubuntu

Changelog

php5 (5.2.3-1ubuntu6.1) gutsy-security; urgency=low

  * SECURITY UPDATE: multiple vulnerabilities.  Thanks to Sean Finney for
    help locating upstream fixes.
  * Add 200-string-wordwrap.patch: wordwrap function can be made to crash.
    Backported upstream fixes (CVE-2007-3998).
  * Add 201-strspn-oob-read.patch: memory reading, possible crash via strspn.
    chunk_split.  Backported upstream fixes (CVE-2007-4657).
  * Add 202-money-format-abuse.patch: money_format format string vulnerable.
    Backported upstream fixes (CVE-2007-4658).
  * Add 203-openssl_make_REQ-overflow.patch: overflow in openssl_make_REQ.
    Applied and corrected upstream fixes (CVE-2007-4662).
  * Add 204-start-session-cookies.patch: overwrite cookie values.
    Applied upstream fixes (CVE-2007-3799).
  * Add 206-chunk_split-fixes.patch: memory reading, possible crash via
    chunk_split.  Merged various upstream fixes (CVE-2007-2872, CVE-2007-4660,
    CVE-2007-4661).
  * Add 206-cookie-nesting-fix.patch: corruption/crashes via deeply nested
    variables.  Backported upstream fixes (CVE-2007-1285, CVE-2007-4670).
  * Add 207-htmlentity-utf8-fix.patch: don't accept partial utf8 sequences.
    Backported upstream fixes (CVE-2007-5898).
  * Add 208-session-id-leak.patch: don't send session id to remote forms.
    Backported upstream fixes (CVE-2007-5899).
  * References
    http://www.php.net/releases/5_2_4.php
    http://www.php.net/releases/5_2_5.php

 -- Kees Cook <email address hidden>   Fri, 19 Oct 2007 12:58:34 -0700

Upload details

Uploaded by:
Kees Cook
Uploaded to:
Gutsy
Original maintainer:
Ubuntu Development Team
Architectures:
any
Section:
web
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
php5_5.2.3.orig.tar.gz 8.9 MiB 5aa265e6003a0442b959bc85f3439c48620f647c37e7afeac0a85fa9d5881576
php5_5.2.3-1ubuntu6.1.diff.gz 123.4 KiB 74a427fc56e3e6cbd3fcfbe89528b3ed2b947dbd58df98dfcebe4abc3e082970
php5_5.2.3-1ubuntu6.1.dsc 1.9 KiB 68694bfb372543f0e11272a692813809762f413a8223053ac5ff25aeda2745ba

View changes file

Binary packages built by this source

libapache2-mod-php5: No summary available for libapache2-mod-php5 in ubuntu gutsy.

No description available for libapache2-mod-php5 in ubuntu gutsy.

php-pear: No summary available for php-pear in ubuntu gutsy.

No description available for php-pear in ubuntu gutsy.

php5: No summary available for php5 in ubuntu gutsy.

No description available for php5 in ubuntu gutsy.

php5-cgi: No summary available for php5-cgi in ubuntu gutsy.

No description available for php5-cgi in ubuntu gutsy.

php5-cli: No summary available for php5-cli in ubuntu gutsy.

No description available for php5-cli in ubuntu gutsy.

php5-common: No summary available for php5-common in ubuntu gutsy.

No description available for php5-common in ubuntu gutsy.

php5-curl: No summary available for php5-curl in ubuntu gutsy.

No description available for php5-curl in ubuntu gutsy.

php5-dev: No summary available for php5-dev in ubuntu gutsy.

No description available for php5-dev in ubuntu gutsy.

php5-gd: No summary available for php5-gd in ubuntu gutsy.

No description available for php5-gd in ubuntu gutsy.

php5-ldap: No summary available for php5-ldap in ubuntu gutsy.

No description available for php5-ldap in ubuntu gutsy.

php5-mhash: No summary available for php5-mhash in ubuntu gutsy.

No description available for php5-mhash in ubuntu gutsy.

php5-mysql: No summary available for php5-mysql in ubuntu gutsy.

No description available for php5-mysql in ubuntu gutsy.

php5-odbc: No summary available for php5-odbc in ubuntu gutsy.

No description available for php5-odbc in ubuntu gutsy.

php5-pgsql: No summary available for php5-pgsql in ubuntu gutsy.

No description available for php5-pgsql in ubuntu gutsy.

php5-pspell: No summary available for php5-pspell in ubuntu gutsy.

No description available for php5-pspell in ubuntu gutsy.

php5-recode: No summary available for php5-recode in ubuntu gutsy.

No description available for php5-recode in ubuntu gutsy.

php5-snmp: No summary available for php5-snmp in ubuntu gutsy.

No description available for php5-snmp in ubuntu gutsy.

php5-sqlite: No summary available for php5-sqlite in ubuntu gutsy.

No description available for php5-sqlite in ubuntu gutsy.

php5-sybase: No summary available for php5-sybase in ubuntu gutsy.

No description available for php5-sybase in ubuntu gutsy.

php5-tidy: No summary available for php5-tidy in ubuntu gutsy.

No description available for php5-tidy in ubuntu gutsy.

php5-xmlrpc: No summary available for php5-xmlrpc in ubuntu gutsy.

No description available for php5-xmlrpc in ubuntu gutsy.

php5-xsl: No summary available for php5-xsl in ubuntu gutsy.

No description available for php5-xsl in ubuntu gutsy.