Ubuntu

“php5” 5.3.5-1ubuntu7.10 source package in Ubuntu

Changelog

php5 (5.3.5-1ubuntu7.10) natty-security; urgency=low

  * SECURITY UPDATE: denial of service via invalid tidy objects
    - debian/patches/CVE-2012-0781.patch: track initialization in
      ext/tidy/tidy.c, added tests to ext/tidy/tests/004.phpt,
      ext/tidy/tests/bug54682.phpt.
    - CVE-2012-0781
  * SECURITY UPDATE: denial of service or possible directory traversal via
    invalid filename.
    - debian/patches/CVE-2012-1172.patch: ensure brackets get closed in
      main/rfc1867.c, add test to tests/basic/bug55500.phpt.
    - CVE-2012-1172
  * SECURITY UPDATE: password truncation via invalid byte
    - debian/patches/CVE-2012-2143.patch: improve logic in
      ext/standard/crypt_freesec.c, add test to
      ext/standard/tests/strings/crypt_chars.phpt.
    - CVE-2012-2143
  * SECURITY UPDATE: crypto() empty salt string issue
    - debian/patches/{php_crypt_revamped,use_system_crypt_fixes}.patch:
      Return fail string on invalid Blowfish salt rounds, fix regression
      when the salt is empty.
    - CVE-2012-2317
  * SECURITY UPDATE: improve php5-cgi query string parameter parsing
    - debian/patches/CVE-2012-233x.patch: improve parsing in
      sapi/cgi/cgi_main.c.
    - CVE-2012-2335
    - CVE-2012-2336
  * SECURITY UPDATE: phar extension heap overflow
    - debian/patches/CVE-2012-2386.patch: check for overflow in
      ext/phar/tar.c.
    - CVE-2012-2386
 -- Marc Deslauriers <email address hidden>   Tue, 12 Jun 2012 15:38:21 -0400

Upload details

Uploaded by:
Marc Deslauriers on 2012-06-19
Uploaded to:
Natty
Original maintainer:
Ubuntu Developers
Component:
main
Architectures:
any
Section:
php
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size MD5 Checksum
php5_5.3.5.orig.tar.gz 12.7 MiB 1568bff29e1d2c742589dda540e7c2d7
php5_5.3.5-1ubuntu7.10.diff.gz 239.3 KiB 5d2269a2d0fa0fcdac94c0a06343069c
php5_5.3.5-1ubuntu7.10.dsc 3.2 KiB f4b259eef33e77cb039daf46b2b3dbcf

Binary packages built by this source

libapache2-mod-php5: No summary available for libapache2-mod-php5 in ubuntu natty.

No description available for libapache2-mod-php5 in ubuntu natty.

libapache2-mod-php5filter: No summary available for libapache2-mod-php5filter in ubuntu natty.

No description available for libapache2-mod-php5filter in ubuntu natty.

php-pear: No summary available for php-pear in ubuntu natty.

No description available for php-pear in ubuntu natty.

php5: No summary available for php5 in ubuntu natty.

No description available for php5 in ubuntu natty.

php5-cgi: No summary available for php5-cgi in ubuntu natty.

No description available for php5-cgi in ubuntu natty.

php5-cli: No summary available for php5-cli in ubuntu natty.

No description available for php5-cli in ubuntu natty.

php5-common: No summary available for php5-common in ubuntu natty.

No description available for php5-common in ubuntu natty.

php5-curl: No summary available for php5-curl in ubuntu natty.

No description available for php5-curl in ubuntu natty.

php5-dbg: No summary available for php5-dbg in ubuntu natty.

No description available for php5-dbg in ubuntu natty.

php5-dev: No summary available for php5-dev in ubuntu natty.

No description available for php5-dev in ubuntu natty.

php5-enchant: No summary available for php5-enchant in ubuntu natty.

No description available for php5-enchant in ubuntu natty.

php5-fpm: No summary available for php5-fpm in ubuntu natty.

No description available for php5-fpm in ubuntu natty.

php5-gd: No summary available for php5-gd in ubuntu natty.

No description available for php5-gd in ubuntu natty.

php5-gmp: No summary available for php5-gmp in ubuntu natty.

No description available for php5-gmp in ubuntu natty.

php5-intl: No summary available for php5-intl in ubuntu natty.

No description available for php5-intl in ubuntu natty.

php5-ldap: No summary available for php5-ldap in ubuntu natty.

No description available for php5-ldap in ubuntu natty.

php5-mysql: No summary available for php5-mysql in ubuntu natty.

No description available for php5-mysql in ubuntu natty.

php5-odbc: No summary available for php5-odbc in ubuntu natty.

No description available for php5-odbc in ubuntu natty.

php5-pgsql: No summary available for php5-pgsql in ubuntu natty.

No description available for php5-pgsql in ubuntu natty.

php5-pspell: No summary available for php5-pspell in ubuntu natty.

No description available for php5-pspell in ubuntu natty.

php5-recode: No summary available for php5-recode in ubuntu natty.

No description available for php5-recode in ubuntu natty.

php5-snmp: No summary available for php5-snmp in ubuntu natty.

No description available for php5-snmp in ubuntu natty.

php5-sqlite: No summary available for php5-sqlite in ubuntu natty.

No description available for php5-sqlite in ubuntu natty.

php5-sybase: No summary available for php5-sybase in ubuntu natty.

No description available for php5-sybase in ubuntu natty.

php5-tidy: No summary available for php5-tidy in ubuntu natty.

No description available for php5-tidy in ubuntu natty.

php5-xmlrpc: No summary available for php5-xmlrpc in ubuntu natty.

No description available for php5-xmlrpc in ubuntu natty.

php5-xsl: No summary available for php5-xsl in ubuntu natty.

No description available for php5-xsl in ubuntu natty.