Oval Definition:oval:org.mitre.oval:def:29150
Revision Date:2015-08-17Version:4
Title:RHSA-2008:0544 -- php security update (Moderate)
Description:Updated PHP packages that fix several security issues are now available forRed Hat Enterprise Linux 3 and 5.This update has been rated as having moderate security impact by the RedHat Security Response Team.PHP is an HTML-embedded scripting language commonly used with the ApacheHTTP Web server.It was discovered that the PHP escapeshellcmdfunction did not properlyescape multi-byte characters which are not valid in the locale used by thescript. This could allow an attacker to bypass quoting restrictions imposedby escapeshellcmdand execute arbitrary commands if the PHP script wasusing certain locales. Scripts using the default UTF-8 locale are notaffected by this issue. (CVE-2008-2051)
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2008:0544-CentOS 3
CESA-2008:0544-CentOS 5
CVE-2007-4782
CVE-2007-5898
CVE-2007-5899
CVE-2008-2051
CVE-2008-2107
CVE-2008-2108
RHSA-2008:0544
Platform(s):CentOS Linux 3
CentOS Linux 5
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 5
Product(s):php
Definition Synopsis
  • Red Hat Enterprise Linux 5 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • AND Packages match section
  • php is earlier than 0:5.1.6-20.el5_2.1
  • OR php-bcmath is earlier than 0:5.1.6-20.el5_2.1
  • OR php-cli is earlier than 0:5.1.6-20.el5_2.1
  • OR php-common is earlier than 0:5.1.6-20.el5_2.1
  • OR php-dba is earlier than 0:5.1.6-20.el5_2.1
  • OR php-devel is earlier than 0:5.1.6-20.el5_2.1
  • OR php-gd is earlier than 0:5.1.6-20.el5_2.1
  • OR php-imap is earlier than 0:5.1.6-20.el5_2.1
  • OR php-ldap is earlier than 0:5.1.6-20.el5_2.1
  • OR php-mbstring is earlier than 0:5.1.6-20.el5_2.1
  • OR php-mysql is earlier than 0:5.1.6-20.el5_2.1
  • OR php-ncurses is earlier than 0:5.1.6-20.el5_2.1
  • OR php-odbc is earlier than 0:5.1.6-20.el5_2.1
  • OR php-pdo is earlier than 0:5.1.6-20.el5_2.1
  • OR php-pgsql is earlier than 0:5.1.6-20.el5_2.1
  • OR php-snmp is earlier than 0:5.1.6-20.el5_2.1
  • OR php-soap is earlier than 0:5.1.6-20.el5_2.1
  • OR php-xml is earlier than 0:5.1.6-20.el5_2.1
  • OR php-xmlrpc is earlier than 0:5.1.6-20.el5_2.1
  • Red Hat Enterprise Linux 3 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 3
  • AND Packages match section
  • php is earlier than 0:4.3.2-48.ent
  • OR php-devel is earlier than 0:4.3.2-48.ent
  • OR php-imap is earlier than 0:4.3.2-48.ent
  • OR php-ldap is earlier than 0:4.3.2-48.ent
  • OR php-mysql is earlier than 0:4.3.2-48.ent
  • OR php-odbc is earlier than 0:4.3.2-48.ent
  • OR php-pgsql is earlier than 0:4.3.2-48.ent
  • BACK