php5 5.3.2-1ubuntu4.5 source package in Ubuntu

Changelog

php5 (5.3.2-1ubuntu4.5) lucid-security; urgency=low

  * SECURITY UPDATE: denial of service and possible memory corruption via
    negative size in HTTP chunked encoding stream
    - debian/patches/CVE-2010-1866.patch: prevent chunk_size from
      overflowing in ext/standard/filters.c.
    - CVE-2010-1866
  * SECURITY UPDATE: arbitrary code execution via empty SQL query
    - debian/patches/CVE-2010-1868.patch: use ecalloc instead of emalloc in
      ext/sqlite/sqlite.c.
    - CVE-2010-1868
  * SECURITY UPDATE: denial of service via fnmatch stack consumption
    - debian/patches/CVE-2010-1917.patch: limit size of pattern in
      ext/standard/file.c.
    - CVE-2010-1917
  * SECURITY UPDATE: arbitrary memory disclosure and possible code
    execution via phar extension
    - debian/patches/CVE-2010-2094.patch: use correct format string in
      ext/phar/dirstream.c, ext/phar/stream.c.
    - CVE-2010-2094
    - CVE-2010-2950
  * SECURITY UPDATE: sensitive information disclosure or arbitrary code
    execution via use-after-free in SplObjectStorage unserializer
    - debian/patches/CVE-2010-2225.patch: fix logic in
      ext/spl/spl_observer.c, ext/standard/{php_var.h,var_unserializer.*},
      add tests to ext/spl/tests.
    - CVE-2010-2225
  * SECURITY UPDATE: sensitive information disclosure via error messages
    - debian/patches/CVE-2010-2531.patch: don't display data when flushing
      output buffer in ext/standard/{var.c,php_var.h}, fix tests in
      ext/standard/tests/general_functions.
    - CVE-2010-2531
  * SECURITY UPDATE: arbitrary session variable modification via crafted
    session variable name
    - debian/patches/CVE-2010-3065.patch: handle PS_UNDEF_MARKER marker in
      ext/session/session.c.
    - CVE-2010-3065
  * debian/patches/lp564920-fix-big-files.patch: Fix downloading of large
    files (LP: #564920)
 -- Marc Deslauriers <email address hidden>   Fri, 17 Sep 2010 08:14:26 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Lucid
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
php
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
php5_5.3.2.orig.tar.gz 13.1 MiB a61f02b3b0a83c5a5b8b71a55c5760d1fb7290f1ec84eef1bdb8e8850a828f2f
php5_5.3.2-1ubuntu4.5.diff.gz 184.9 KiB 6eca7387060b867e9a22e3b466d1976053ac33aa527c9f2433ab245179a8abec
php5_5.3.2-1ubuntu4.5.dsc 2.5 KiB 229802416ae1bf4a2f93a764ff31af544b41ee45816eac4b3e7cd459a73d81be

View changes file

Binary packages built by this source

libapache2-mod-php5: No summary available for libapache2-mod-php5 in ubuntu lucid.

No description available for libapache2-mod-php5 in ubuntu lucid.

libapache2-mod-php5filter: No summary available for libapache2-mod-php5filter in ubuntu lucid.

No description available for libapache2-mod-php5filter in ubuntu lucid.

php-pear: No summary available for php-pear in ubuntu lucid.

No description available for php-pear in ubuntu lucid.

php5: No summary available for php5 in ubuntu lucid.

No description available for php5 in ubuntu lucid.

php5-cgi: No summary available for php5-cgi in ubuntu lucid.

No description available for php5-cgi in ubuntu lucid.

php5-cli: No summary available for php5-cli in ubuntu lucid.

No description available for php5-cli in ubuntu lucid.

php5-common: No summary available for php5-common in ubuntu lucid.

No description available for php5-common in ubuntu lucid.

php5-curl: No summary available for php5-curl in ubuntu lucid.

No description available for php5-curl in ubuntu lucid.

php5-dbg: No summary available for php5-dbg in ubuntu lucid.

No description available for php5-dbg in ubuntu lucid.

php5-dev: No summary available for php5-dev in ubuntu lucid.

No description available for php5-dev in ubuntu lucid.

php5-enchant: No summary available for php5-enchant in ubuntu lucid.

No description available for php5-enchant in ubuntu lucid.

php5-gd: No summary available for php5-gd in ubuntu lucid.

No description available for php5-gd in ubuntu lucid.

php5-gmp: No summary available for php5-gmp in ubuntu lucid.

No description available for php5-gmp in ubuntu lucid.

php5-intl: No summary available for php5-intl in ubuntu lucid.

No description available for php5-intl in ubuntu lucid.

php5-ldap: No summary available for php5-ldap in ubuntu lucid.

No description available for php5-ldap in ubuntu lucid.

php5-mysql: No summary available for php5-mysql in ubuntu lucid.

No description available for php5-mysql in ubuntu lucid.

php5-odbc: No summary available for php5-odbc in ubuntu lucid.

No description available for php5-odbc in ubuntu lucid.

php5-pgsql: No summary available for php5-pgsql in ubuntu lucid.

No description available for php5-pgsql in ubuntu lucid.

php5-pspell: No summary available for php5-pspell in ubuntu lucid.

No description available for php5-pspell in ubuntu lucid.

php5-recode: No summary available for php5-recode in ubuntu lucid.

No description available for php5-recode in ubuntu lucid.

php5-snmp: No summary available for php5-snmp in ubuntu lucid.

No description available for php5-snmp in ubuntu lucid.

php5-sqlite: No summary available for php5-sqlite in ubuntu lucid.

No description available for php5-sqlite in ubuntu lucid.

php5-sybase: No summary available for php5-sybase in ubuntu lucid.

No description available for php5-sybase in ubuntu lucid.

php5-tidy: No summary available for php5-tidy in ubuntu lucid.

No description available for php5-tidy in ubuntu lucid.

php5-xmlrpc: No summary available for php5-xmlrpc in ubuntu lucid.

No description available for php5-xmlrpc in ubuntu lucid.

php5-xsl: No summary available for php5-xsl in ubuntu lucid.

No description available for php5-xsl in ubuntu lucid.