Oval Definition:oval:org.mitre.oval:def:13706
Revision Date:2014-06-30Version:21
Title:USN-862-1 -- php5 vulnerabilities
Description:Maksymilian Arciemowicz discovered that PHP did not properly validate arguments to the dba_replace function. If a script passed untrusted input to the dba_replace function, an attacker could truncate the database. This issue only applied to Ubuntu 6.06 LTS, 8.04 LTS, and 8.10. It was discovered that PHP�s php_openssl_apply_verification_policy function did not correctly handle SSL certificates with zero bytes in the Common Name. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. It was discovered that PHP did not properly handle certain malformed images when being parsed by the Exif module. A remote attacker could exploit this flaw and cause the PHP server to crash, resulting in a denial of service. Grzegorz Stachowiak discovered that PHP did not properly enforce restrictions in the tempnam function. An attacker could exploit this issue to bypass safe_mode restrictions. Grzegorz Stachowiak discovered that PHP did not properly enforce restrictions in the posix_mkfifo function. An attacker could exploit this issue to bypass open_basedir restrictions. Bogdan Calin discovered that PHP did not limit the number of temporary files created when handling multipart/form-data POST requests. A remote attacker could exploit this flaw and cause the PHP server to consume all available resources, resulting in a denial of service. ATTENTION: This update changes previous PHP behaviour by limiting the number of files in a POST request to 50. This may be increased by adding a "max_file_uploads" directive to the php.ini configuration file. It was discovered that PHP did not properly enforce restrictions in the proc_open function. An attacker could exploit this issue to bypass safe_mode_protected_env_vars restrictions and possibly execute arbitrary code with application privileges
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-7068
CVE-2009-3291
CVE-2009-3292
CVE-2009-3557
CVE-2009-3558
CVE-2009-4017
CVE-2009-4018
USN-862-1
USN-862-1
Platform(s):Ubuntu 6.06
Ubuntu 8.04
Ubuntu 8.10
Ubuntu 9.04
Ubuntu 9.10
Product(s):php5
Definition Synopsis
  • Release section
  • Ubuntu 8.04 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • php-pear DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5 DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • php5-cli DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-cgi DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-tidy DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-recode DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-sybase DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-pspell DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-curl DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-snmp DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-ldap DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-common DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-odbc DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-dev DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-pgsql DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-xsl DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-mysql DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-xmlrpc DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-sqlite DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-gd DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-gmp DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR libapache2-mod-php5 DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR php5-mhash DPKG is earlier than 5.2.4-2ubuntu5.9
  • OR Release section
  • Ubuntu 8.10 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • php-pear DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5 DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • php5-recode DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-cgi DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-curl DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-snmp DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-mysql DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-odbc DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-xsl DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-gd DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR libapache2-mod-php5 DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-mhash DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-tidy DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-dev DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-pgsql DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-gmp DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-xmlrpc DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-sqlite DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-ldap DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-cli DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-sybase DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR libapache2-mod-php5filter DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-pspell DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-common DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR php5-dbg DPKG is earlier than 5.2.6-2ubuntu4.5
  • OR Release section
  • Ubuntu 9.10 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • php-pear DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5 DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • php5-recode DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-cgi DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-curl DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-snmp DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-mysql DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-odbc DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-xsl DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-gd DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR libapache2-mod-php5 DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-mhash DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-tidy DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-dev DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-pgsql DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-gmp DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-xmlrpc DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-sqlite DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-ldap DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-cli DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-sybase DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR libapache2-mod-php5filter DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-pspell DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-common DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR php5-dbg DPKG is earlier than 5.2.10.dfsg.1-2ubuntu6.3
  • OR Release section
  • Ubuntu 6.06 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • php-pear DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5 DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is powerpc
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • AND Packages section
  • php5-cli DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-cgi DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR libapache2-mod-php5 DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-recode DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-sybase DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-xmlrpc DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-curl DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-snmp DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-ldap DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-mysqli DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-odbc DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-pgsql DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-sqlite DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-mysql DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-xsl DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-gd DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-common DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-dev DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR php5-mhash DPKG is earlier than 5.1.2-1ubuntu3.17
  • OR Release section
  • Ubuntu 9.04 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • php-pear DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5 DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • php5-recode DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-cgi DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-curl DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-snmp DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-mysql DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-odbc DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-xsl DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-gd DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR libapache2-mod-php5 DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-mhash DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-tidy DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-dev DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-pgsql DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-gmp DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-xmlrpc DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-sqlite DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-ldap DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-cli DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-sybase DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR libapache2-mod-php5filter DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-pspell DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-common DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • OR php5-dbg DPKG is earlier than 5.2.6.dfsg.1-3ubuntu4.4
  • BACK