Ubuntu

“php5” 5.3.6-13ubuntu3.9 source package in The Oneiric Ocelot

Publishing history

5.3.6-13ubuntu3.9
SUPERSEDED: Oneiric pocket Updates in component main and section php
  • Removed from disk on 2013-03-15.
  • Removal requested on 2013-03-14.
  • Superseded on 2013-03-13 by php5 - 5.3.6-13ubuntu3.10
  • Published on 2012-09-17
  • Copied from ubuntu oneiric in Private PPA for Ubuntu Security Team by Ubuntu Archive Robot
5.3.6-13ubuntu3.9
SUPERSEDED: Oneiric pocket Security in component main and section php
  • Removed from disk on 2013-03-15.
  • Removal requested on 2013-03-14.
  • Superseded on 2013-03-13 by php5 - 5.3.6-13ubuntu3.10
  • Published on 2012-09-17
  • Copied from ubuntu oneiric in Private PPA for Ubuntu Security Team by Marc Deslauriers

Builds

Changelog

php5 (5.3.6-13ubuntu3.9) oneiric-security; urgency=low

  * SECURITY UPDATE: HTTP response-splitting issue with %0D sequences
    - debian/patches/CVE-2011-1398.patch: properly handle %0D and NUL in
      main/SAPI.c, added tests to ext/standard/tests/*, fix test suite
      failures in ext/phar/phar_object.c.
    - CVE-2011-1398
    - CVE-2012-4388
  * SECURITY UPDATE: denial of service and possible code execution via
    _php_stream_scandir function (LP: #1028064)
    - debian/patches/CVE-2012-2688.patch: prevent overflow in
      main/streams/streams.c.
    - CVE-2012-2688
  * SECURITY UPDATE: denial of service via PDO extension crafted parameter
    - debian/patches/CVE-2012-3450.patch: improve logic in
      ext/pdo/pdo_sql_parser.re, regenerate ext/pdo/pdo_sql_parser.c, add
      test to ext/pdo_mysql/tests/bug_61755.phpt.
    - CVE-2012-3450
 -- Marc Deslauriers <email address hidden>   Wed, 12 Sep 2012 09:09:05 -0400