Format: 1.7 Date: Thu, 28 Apr 2011 05:23:21 -0700 Source: php5 Binary: php5 php5-common libapache2-mod-php5 php5-cgi php5-cli php5-dev php-pear php5-curl php5-gd php5-gmp php5-ldap php5-mhash php5-mysql php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl Architecture: lpia_translations lpia Version: 5.2.4-2ubuntu5.15 Distribution: hardy Urgency: low Maintainer: Ubuntu/i386 Build Daemon Changed-By: Steve Beattie Description: libapache2-mod-php5 - server-side, HTML-embedded scripting language (apache 2 module) php-pear - PEAR - PHP Extension and Application Repository php5 - server-side, HTML-embedded scripting language (meta-package) php5-cgi - server-side, HTML-embedded scripting language (CGI binary) php5-cli - command-line interpreter for the php5 scripting language php5-common - Common files for packages built from the php5 source php5-curl - CURL module for php5 php5-dev - Files for PHP5 module development php5-gd - GD module for php5 php5-gmp - GMP module for php5 php5-ldap - LDAP module for php5 php5-mhash - MHASH module for php5 php5-mysql - MySQL module for php5 php5-odbc - ODBC module for php5 php5-pgsql - PostgreSQL module for php5 php5-pspell - pspell module for php5 php5-recode - recode module for php5 php5-snmp - SNMP module for php5 php5-sqlite - SQLite module for php5 php5-sybase - Sybase / MS SQL Server module for php5 php5-tidy - tidy module for php5 php5-xmlrpc - XML-RPC module for php5 php5-xsl - XSL module for php5 Changes: php5 (5.2.4-2ubuntu5.15) hardy-security; urgency=low . * SECURITY UPDATE: arbitrary files removal via cronjob - debian/php5-common.php5.cron.d: take greater care when removing session files. - http://git.debian.org/?p=pkg-php%2Fphp.git;a=commitdiff_plain;h=d09fd04ed7bfcf7f008360c6a42025108925df09 - CVE-2011-0441 * SECURITY UPDATE: symlink tmp races in pear install - debian/patches/php5-pear-CVE-2011-1072.patch: improved tempfile handling. - debian/rules: apply patch manually after unpacking PEAR phar archive. - CVE-2011-1072 * SECURITY UPDATE: more symlink races in pear install - debian/patches/php5-pear-CVE-2011-1144.patch: add TOCTOU save file handler. - debian/rules: apply patch manually after unpacking PEAR phar archive. - CVE-2011-1144 * SECURITY UPDATE: use-after-free vulnerability - debian/patches/php5-CVE-2010-4697.patch: retain reference to object until getter/setter are done. - CVE-2010-4697 * SECURITY UPDATE: denial of service through application crash with invalid images - debian/patches/php5-CVE-2010-4698.patch: verify anti-aliasing steps are either 4 or 16. - CVE-2010-4698 * SECURITY UPDATE: denial of service through application crash - debian/patches/php5-CVE-2011-0421.patch: fail operation gracefully when handling zero sized zipfile with the FL_UNCHANGED argument - CVE-2011-0421 * SECURITY UPDATE: denial of service through application crash when handling images with invalid exif tags - debian/patches/php5-CVE-2011-0708.patch: stricter exif checking - CVE-2011-0708 * SECURITY UPDATE: denial of service and possible data disclosure through integer overflow - debian/patches/php5-CVE-2011-1092.patch: better boundary condition checks in shmop_read() - CVE-2011-1092 * SECURITY UPDATE: use-after-free vulnerability - debian/patches/php5-CVE-2011-1148.patch: improve reference counting - CVE-2011-1148 * SECURITY UPDATE: denial of service through buffer overflow crash (code execution mitigated by compilation with Fortify Source) - debian/patches/php5-CVE-2011-1464.patch: limit amount of precision to ensure fitting within MAX_BUF_SIZE - CVE-2011-1464 * SECURITY UPDATE: denial of service through application crash via integer overflow. - debian/patches/php5-CVE-2011-1466.patch: improve boundary condition checking in SdnToJulian() - CVE-2011-1466 * SECURITY UPDATE: denial of service through application crash when using HTTP proxy with the FTP wrapper - debian/patches/php5-CVE-2011-1469.patch: improve pointer handling - CVE-2011-1469 * SECURITY UPDATE: denial of service through application crash when handling ziparchive streams - debian/patches/php5-CVE-2011-1470.patch: set necessary elements of the meta data structure - CVE-2011-1470 * SECURITY UPDATE: denial of service through application crash when handling malformed zip files - debian/patches/php5-CVE-2011-1471.patch: correct integer signedness error when handling zip_fread() return value. - CVE-2011-1471 Files: 886870988dfe9c78f8dd18b6dd2b83ae 541 raw-translations - php5_5.2.4-2ubuntu5.15_lpia_translations.tar.gz abf268771e26d9d68e4f33bf24a425ec 319078 web optional php5-common_5.2.4-2ubuntu5.15_lpia.deb dfdbb6ea8fb4aaf4783189487145fdf6 2454610 web optional libapache2-mod-php5_5.2.4-2ubuntu5.15_lpia.deb a683aaf130a9ce8d206dab7a62536c7d 4880850 web optional php5-cgi_5.2.4-2ubuntu5.15_lpia.deb edf8ea662df01827464b02d18ca5802d 2463060 web optional php5-cli_5.2.4-2ubuntu5.15_lpia.deb e74b3ebe4874ee0fe3157c617e69f8c6 364830 devel optional php5-dev_5.2.4-2ubuntu5.15_lpia.deb 70273028609a85d0115984ab0539eed2 23284 web optional php5-curl_5.2.4-2ubuntu5.15_lpia.deb e1ef7bfb4cabeb4aafed89f5bb5523a5 33138 web optional php5-gd_5.2.4-2ubuntu5.15_lpia.deb 50b4a80299ecfcab327080c95e048c35 15024 web optional php5-gmp_5.2.4-2ubuntu5.15_lpia.deb 654669d448b359792c61c70f938e61ec 18100 web optional php5-ldap_5.2.4-2ubuntu5.15_lpia.deb b71d23fbd3bf5a06ffd6ebe8cd6fb6ea 5102 web optional php5-mhash_5.2.4-2ubuntu5.15_lpia.deb 9da6bb2a5a08785ecc239476b383bfed 64308 web optional php5-mysql_5.2.4-2ubuntu5.15_lpia.deb 3e299131e6d1644f9ceb0af984f277df 33936 web optional php5-odbc_5.2.4-2ubuntu5.15_lpia.deb 8426715eda0f5c5d09ba804d083f8b45 50860 web optional php5-pgsql_5.2.4-2ubuntu5.15_lpia.deb 6daff9721aab5bb914a091bac0fbe5c3 8636 web optional php5-pspell_5.2.4-2ubuntu5.15_lpia.deb 1704a85d3ac2e342de8207f76955651e 4718 web optional php5-recode_5.2.4-2ubuntu5.15_lpia.deb 5e4dd5d8c009911cb02785690b888efd 11574 web optional php5-snmp_5.2.4-2ubuntu5.15_lpia.deb e233913c43161ba7b00d306da584b19c 33742 web optional php5-sqlite_5.2.4-2ubuntu5.15_lpia.deb a0f552356da56d7930ec5111ca0163fc 26126 web optional php5-sybase_5.2.4-2ubuntu5.15_lpia.deb 09407542d11838553a1289c4fe8880a1 16054 web optional php5-tidy_5.2.4-2ubuntu5.15_lpia.deb 2b5556c86fdfb8113f03f3c9a3444edd 35464 web optional php5-xmlrpc_5.2.4-2ubuntu5.15_lpia.deb 1239767f6b1a27ffb624a45e51deae23 12432 web optional php5-xsl_5.2.4-2ubuntu5.15_lpia.deb Original-Maintainer: Debian PHP Maintainers