Oval Definition:oval:com.redhat.rhsa:def:20050405
Revision Date:2005-04-28Version:502
Title:RHSA-2005:405: PHP security update (Moderate)
Description:PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Web server.

A bug was found in the way PHP processes IFF and JPEG images. It is possible to cause PHP to consume CPU resources for a short period of time by supplying a carefully crafted IFF or JPEG image. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2005-0524 and CAN-2005-0525 to these issues.

A buffer overflow bug was also found in the way PHP processes EXIF image headers. It is possible for an attacker to construct an image file in such a way that it could execute arbitrary instructions when processed by PHP. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-1042 to this issue.

A denial of service bug was found in the way PHP processes EXIF image headers. It is possible for an attacker to cause PHP to enter an infinite loop for a short period of time by supplying a carefully crafted image file to PHP for processing. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-1043 to this issue.

Several bug fixes are also included in this update:

- The security fixes in RHSA-2004-687 to the "unserializer" code introduced some performance issues.

- In the gd extension, the "imagecopymerge" function did not correctly handle transparency. The original image was being obscured in the resultant image.

- In the curl extension, safe mode was not enforced for 'file:///' URL lookups (CAN-2004-1392).

Users of PHP should upgrade to these updated packages, which contain backported fixes for these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2004-1392
CVE-2005-0524
CVE-2005-0525
CVE-2005-1042
CVE-2005-1043
RHSA-2005:405-01
Platform(s):Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 3 is installed
  • AND Package Information
  • php-odbc is earlier than 0:4.3.2-23.ent
  • AND php-odbc is signed with Red Hat master key
  • OR
  • php-mysql is earlier than 0:4.3.2-23.ent
  • AND php-mysql is signed with Red Hat master key
  • OR
  • php is earlier than 0:4.3.2-23.ent
  • AND php is signed with Red Hat master key
  • OR
  • php-pgsql is earlier than 0:4.3.2-23.ent
  • AND php-pgsql is signed with Red Hat master key
  • OR
  • php-devel is earlier than 0:4.3.2-23.ent
  • AND php-devel is signed with Red Hat master key
  • OR
  • php-imap is earlier than 0:4.3.2-23.ent
  • AND php-imap is signed with Red Hat master key
  • OR
  • php-ldap is earlier than 0:4.3.2-23.ent
  • AND php-ldap is signed with Red Hat master key
  • BACK