Oval Definition:oval:org.mitre.oval:def:13775
Revision Date:2014-06-30Version:21
Title:USN-761-1 -- php5 vulnerabilities
Description:It was discovered that PHP did not sanitize certain error messages when display_errors is enabled, which could result in browsers becoming vulnerable to cross-site scripting attacks when processing the output. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain. It was discovered that PHP did not properly handle the mbstring.func_overload setting within .htaccess files when using virtual hosts. A virtual host administrator could use this flaw to cause settings to be applied to other virtual hosts on the same server. It was discovered that PHP did not properly handle certain malformed strings when being parsed by the json_decode function. A remote attacker could exploit this flaw and cause the PHP server to crash, resulting in a denial of service. This issue only affected Ubuntu 8.04 and 8.10
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-5814
CVE-2009-0754
CVE-2009-1271
USN-761-1
USN-761-1
Platform(s):Ubuntu 6.06
Ubuntu 8.04
Ubuntu 8.10
Product(s):php5
Definition Synopsis
  • Release section
  • Ubuntu 8.04 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • php-pear DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5 DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • php5-cli DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-cgi DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-tidy DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-recode DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-sybase DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-pspell DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-curl DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-snmp DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-ldap DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-common DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-odbc DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-dev DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-pgsql DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-xsl DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-mysql DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-xmlrpc DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-sqlite DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-gd DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-gmp DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR libapache2-mod-php5 DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR php5-mhash DPKG is earlier than 5.2.4-2ubuntu5.6
  • OR Release section
  • Ubuntu 6.06 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • php-pear DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5 DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is powerpc
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • AND Packages section
  • php5-cli DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-cgi DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR libapache2-mod-php5 DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-recode DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-sybase DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-xmlrpc DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-curl DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-snmp DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-ldap DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-mysqli DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-odbc DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-pgsql DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-sqlite DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-mysql DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-xsl DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-gd DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-common DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-dev DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR php5-mhash DPKG is earlier than 5.1.2-1ubuntu3.14
  • OR Release section
  • Ubuntu 8.10 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • php-pear DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5 DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • php5-recode DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-cgi DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-curl DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-snmp DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-mysql DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-odbc DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-xsl DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-gd DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR libapache2-mod-php5 DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-mhash DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-tidy DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-dev DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-pgsql DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-gmp DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-xmlrpc DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-sqlite DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-ldap DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-cli DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-sybase DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR libapache2-mod-php5filter DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-pspell DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-common DPKG is earlier than 5.2.6-2ubuntu4.2
  • OR php5-dbg DPKG is earlier than 5.2.6-2ubuntu4.2
  • BACK