Oval Definition:oval:org.mitre.oval:def:7889
Revision Date:2014-06-23Version:18
Title:DSA-1572 php5 -- several vulnerabilities
Description:Several vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language. The Common Vulnerabilities and Exposures project identifies the following problems: The glob function allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter. Integer overflow allows context-dependent attackers to cause a denial of service and possibly have other impact via a printf format parameter with a large width specifier. Stack-based buffer overflow in the FastCGI SAPI. The escapeshellcmd API function could be attacked via incomplete multibyte chars.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-3806
CVE-2008-1384
CVE-2008-2050
CVE-2008-2051
DSA-1572
Platform(s):Debian GNU/Linux 4.0
Product(s):php5
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • php-pear is earlier than 5.2.0-8+etch11
  • OR php5 is earlier than 5.2.0-8+etch11
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • libapache-mod-php5 is earlier than 5.2.0-8+etch11
  • OR php5-recode is earlier than 5.2.0-8+etch11
  • OR php5-cgi is earlier than 5.2.0-8+etch11
  • OR php5-curl is earlier than 5.2.0-8+etch11
  • OR php5-snmp is earlier than 5.2.0-8+etch11
  • OR php5-mysql is earlier than 5.2.0-8+etch11
  • OR php5-odbc is earlier than 5.2.0-8+etch11
  • OR php5-xsl is earlier than 5.2.0-8+etch11
  • OR php5-gd is earlier than 5.2.0-8+etch11
  • OR libapache2-mod-php5 is earlier than 5.2.0-8+etch11
  • OR php5-mhash is earlier than 5.2.0-8+etch11
  • OR php5-tidy is earlier than 5.2.0-8+etch11
  • OR php5-mcrypt is earlier than 5.2.0-8+etch11
  • OR php5-dev is earlier than 5.2.0-8+etch11
  • OR php5-pgsql is earlier than 5.2.0-8+etch11
  • OR php5-xmlrpc is earlier than 5.2.0-8+etch11
  • OR php5-imap is earlier than 5.2.0-8+etch11
  • OR php5-sqlite is earlier than 5.2.0-8+etch11
  • OR php5-ldap is earlier than 5.2.0-8+etch11
  • OR php5-cli is earlier than 5.2.0-8+etch11
  • OR php5-sybase is earlier than 5.2.0-8+etch11
  • OR php5-pspell is earlier than 5.2.0-8+etch11
  • OR php5-common is earlier than 5.2.0-8+etch11
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is i386
  • OR Installed architecture is amd64
  • AND php5-interbase is earlier than 5.2.0-8+etch11
  • BACK