| Nessus Plugin ID: 24581 | Name: MDKSA-2006:196: php |
| CVE References: CVE-2006-1494 (cve.mitre.org, nvd.nist.gov)  CVE-2006-5465 (cve.mitre.org, nvd.nist.gov)  CVE-2006-5706 (cve.mitre.org, nvd.nist.gov)  |
| SANS/FBI TOP20 Reference: |
| Group/Family: Mandriva Local Security Checks |
| Risk: High |
Description: Synopsis :
The remote host is missing the patch for the advisory MDKSA-2006:196 (php).
Description :
The Hardened-PHP Project discovered buffer overflows in
htmlentities/htmlspecialchars internal routines to the PHP Project.
The purpose of these functions is to be filled with user input.
(The overflow can only be when UTF-8 is used) (CVE-2006-5465)
Unspecified vulnerabilities in PHP, probably before 5.2.0, allow local
users to bypass open_basedir restrictions and perform unspecified
actions via unspecified vectors involving the (1) chdir and (2) tempnam
functions. NOTE: the tempnam vector might overlap CVE-2006-1494.
(CVE-2006-5706)
Updated packages have been patched to correct these issues. Users must
restart Apache for the changes to take effect.
See also :
http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:196
Solution :
Apply the newest security patches from Mandriva.
/ CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
|
| Created: 2007-03-07 20:00:54 | Last Changed: 2009-06-16 17:29:58 |