| Nessus Plugin ID: 27148 | Name: SuSE Security Update: php5: security update (apache2-mod_php5-2238) |
| CVE References: CVE-2006-5465 (cve.mitre.org, nvd.nist.gov)  |
| SANS/FBI TOP20 Reference: |
| Group/Family: SuSE Local Security Checks |
| Risk: High |
Description: Synopsis :
The remote SuSE system is missing the security patch apache2-mod_php5-2238
Description :
This update fixes the following security problems in the
PHP scripting language:
- CVE-2006-5465: Various buffer overflows in
htmlentities/htmlspecialchars internal routines could be
used to crash the PHP interpreter or potentially execute
code, depending on the PHP application used.
- A missing open_basedir check inside chdir() function was
added.
- A tempnam() openbasedir bypass was fixed.
- A possible buffer overflow in stream_socket_client() when
using 'bindto' + IPv6 was fixed.
- Do not build php5 with --enable-sigchld.
Solution :
Install the apache2-mod_php5-2238 security patch by using 'yast', for example.
/ CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
|
| Created: 2007-10-21 23:07:07 | Last Changed: 2010-08-24 18:09:02 |