drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in php
| Name: |
Mehrere Probleme in php |
|
| ID: |
TLSA-2009-2 |
|
| Distribution: |
TurboLinux |
|
| Plattformen: |
Turbolinux Client 2008, Turbolinux 10 Server, Turbolinux 10 Server x64 Edition, Turbolinux Appliance Server 2.0, Turbolinux 11 Server x64 Edition, Turbolinux 11 Server, Turbolinux Appliance Server 3.0, Turbolinux Appliance Server 3.0 x64 Edition, Turbolinux Multimedia, Turbolinux Personal, Turbolinux Appliance Server 1.0 Hosting Edition, Turbolinux Appliance Server 1.0 Workgroup Edition |
|
| Datum: |
Do, 29. Januar 2009, 03:50 |
|
| Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4782
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4850
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1384
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2050
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2051
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3658
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3659
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3660
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5498 |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
-------------------------------------------------------------------------- Turbolinux Security Advisory TLSA-2009-2 http://www.turbolinux.co.jp/security/ security-team@turbolinux.co.jp --------------------------------------------------------------------------
Original released date: 28 Jan 2009 Last revised: 28 Jan 2009
Package: php
Summary: Multiple vulnerabilities exist in php
More information: PHP is an HTML-embedded scripting language.
Multiple vulnerabilities have been discovered in php.
Affected Products: - Turbolinux Client 2008 - Turbolinux Appliance Server 3.0 x64 Edition - Turbolinux Appliance Server 3.0 - Turbolinux 11 Server x64 Edition - Turbolinux 11 Server - Turbolinux Appliance Server 2.0 - Turbolinux 10 Server x64 Edition - Turbolinux Appliance Server 1.0 Hosting Edition - Turbolinux Appliance Server 1.0 Workgroup Edition - Turbolinux 10 Server - Turbolinux Multimedia - Turbolinux Personal
<Turbolinux Client 2008>
Source Packages Size: MD5
php-5.2.4-16.src.rpm 7657920 18ba1b4787c3a0a3ab337521aa50b5be
Binary Packages Size: MD5
php-5.2.4-16.i586.rpm 4070267 93860f19769bb823aad4106de23b69ba php-cli-5.2.4-16.i586.rpm 2644751 f0ca835fea35b1dd262c201b2ecfa3bd php-common-5.2.4-16.i586.rpm 278325 646fa8c7a8aa7caa859007d9f2c2e048 php-devel-5.2.4-16.i586.rpm 551099 94fc6d881f3d008d1b2669f5e9dd8bb5
<Turbolinux Appliance Server 3.0 x64 Edition>
Source Packages Size: MD5
php-5.2.4-16.src.rpm 7657424 d7d8e223224959fe02241b853a9ad9a1
Binary Packages Size: MD5
php-5.2.4-16.x86_64.rpm 4160296 8b218c49fc55c48f1e3e5d1059ea96ec php-bcmath-5.2.4-16.x86_64.rpm 46170 061acbe68712a18ff348578b077bb9e9 php-cli-5.2.4-16.x86_64.rpm 2629551 0fb731aa43c8f76ec8c611e9cb01db38 php-common-5.2.4-16.x86_64.rpm 283454 ee8d9d71fb9b1506e71828cc98a7040e php-dba-5.2.4-16.x86_64.rpm 60787 d843c628cb8a5705d8c10abbf6086c30 php-embedded-5.2.4-16.x86_64.rpm 1372647 64884bd5d82bb409c0e67d34fd2e36a8 php-gd-5.2.4-16.x86_64.rpm 213656 fd3b0c4ead3f171e26e8b2f473dbd7d1 php-imap-5.2.4-16.x86_64.rpm 87121 86f2d55616d0b684d6114263d93031c3 php-ldap-5.2.4-16.x86_64.rpm 50907 a3e42cf0c917290c009adba1f404b5e4 php-mbstring-5.2.4-16.x86_64.rpm 2164973 a31def8817f7ef56d83eecdabd719f02 php-mcrypt-5.2.4-16.x86_64.rpm 38679 6ce49e923bfd34c4d3c4d85ddc1f9df0 php-mhash-5.2.4-16.x86_64.rpm 19956 8d8248ae180a2abc71b4391a0b3dda38 php-mssql-5.2.4-16.x86_64.rpm 54141 af01a3dc6e247d42eb337c9b1ee55f26 php-mysql-5.2.4-16.x86_64.rpm 156990 928d69722a95fc408fa0728dc27070e1 php-ncurses-5.2.4-16.x86_64.rpm 60573 4c624b74e3dc4bd9108cc9ad1eff433a php-odbc-5.2.4-16.x86_64.rpm 85277 bc3257026ec55177798a2c4bb32272ec php-pdo-5.2.4-16.x86_64.rpm 111510 cc744b01c0e5714f8f94419e1cac2599 php-pgsql-5.2.4-16.x86_64.rpm 122762 fb7f251f1f7bb601f5eca76631e0590d php-snmp-5.2.4-16.x86_64.rpm 31463 39baf7eb4fb36760fe514c035d3723b0 php-soap-5.2.4-16.x86_64.rpm 270624 edad391a77a7a0404a62782c84f7acb7 php-tidy-5.2.4-16.x86_64.rpm 46196 3b73165793d20ba1b740b1aa399b4d1f php-xml-5.2.4-16.x86_64.rpm 187194 028fe2521843a86abf2d3fa49a72995c
<Turbolinux Appliance Server 3.0>
Source Packages Size: MD5
php-5.2.4-16.src.rpm 7657424 d7d8e223224959fe02241b853a9ad9a1
Binary Packages Size: MD5
php-5.2.4-16.i686.rpm 3827984 c48ecf3cb16e43d7340f1cc7cf6db4d9 php-bcmath-5.2.4-16.i686.rpm 36065 70bead6d7250a0ce220ee1ecff1c1f30 php-cli-5.2.4-16.i686.rpm 2486167 e5e93cd519b4cfdc5b069fa010a8fb3c php-common-5.2.4-16.i686.rpm 272262 6ce74a9d0e4ecd8535ad97d7cec8e7c1 php-dba-5.2.4-16.i686.rpm 56406 42312114e1636bcc8c9ee8cf4ce35e84 php-embedded-5.2.4-16.i686.rpm 1264892 1d356a7e80b857fe35f0eef49d179d86 php-gd-5.2.4-16.i686.rpm 200242 ac9c18e80144b9b98ef52c84fbc2ce03 php-imap-5.2.4-16.i686.rpm 79720 be3191dd7e0f54348eec0ffdc4de685e php-ldap-5.2.4-16.i686.rpm 46613 b297afa99e9168dd01d8abd4d9c4cd74 php-mbstring-5.2.4-16.i686.rpm 2123277 a4b7dcc58e6c6a154b159acc4ee3afc5 php-mcrypt-5.2.4-16.i686.rpm 33187 54bd7c7588775f5243b4b6479e188aed php-mhash-5.2.4-16.i686.rpm 19154 6e8cb0550487cc84081fd2a41078b4b0 php-mssql-5.2.4-16.i686.rpm 50704 3bc50b1a2d9139f08c8d02267667da9a php-mysql-5.2.4-16.i686.rpm 139741 db913fd436718d5bf17abc0e04a346d1 php-ncurses-5.2.4-16.i686.rpm 54232 a78a4623032f5d0b770073e5cb0bbab4 php-odbc-5.2.4-16.i686.rpm 77571 f40d3e4ed751e950a6ab236d9b7c6b61 php-pdo-5.2.4-16.i686.rpm 103221 d891b29078ebae5afc2764e3eaea1175 php-pgsql-5.2.4-16.i686.rpm 111215 a51fbd1eaa23305e41802baef101ad31 php-snmp-5.2.4-16.i686.rpm 29055 8fecc9bda8b45d635b863e9f53e3f62b php-soap-5.2.4-16.i686.rpm 266375 5856778ece30d4ed3be6e4e5734ee3f6 php-tidy-5.2.4-16.i686.rpm 42908 15236a0a3374d50d6682f656ee898302 php-xml-5.2.4-16.i686.rpm 164335 6338fd019bc303eff2197361f82e3816 php-xmlrpc-5.2.4-16.i686.rpm 83679 ea76d2cd504ecd0a76b23aa7c28511ca
<Turbolinux 11 Server x64 Edition>
Source Packages Size: MD5
php-5.2.4-16.src.rpm 7657424 d7d8e223224959fe02241b853a9ad9a1
Binary Packages Size: MD5
php-5.2.4-16.x86_64.rpm 4160296 8b218c49fc55c48f1e3e5d1059ea96ec php-bcmath-5.2.4-16.x86_64.rpm 46170 061acbe68712a18ff348578b077bb9e9 php-cli-5.2.4-16.x86_64.rpm 2629551 0fb731aa43c8f76ec8c611e9cb01db38 php-common-5.2.4-16.x86_64.rpm 283454 ee8d9d71fb9b1506e71828cc98a7040e php-dba-5.2.4-16.x86_64.rpm 60787 d843c628cb8a5705d8c10abbf6086c30 php-devel-5.2.4-16.x86_64.rpm 570273 aa610822fc17baa87ef7cd722c0cf970 php-embedded-5.2.4-16.x86_64.rpm 1372647 64884bd5d82bb409c0e67d34fd2e36a8 php-gd-5.2.4-16.x86_64.rpm 213656 fd3b0c4ead3f171e26e8b2f473dbd7d1 php-imap-5.2.4-16.x86_64.rpm 87121 86f2d55616d0b684d6114263d93031c3 php-ldap-5.2.4-16.x86_64.rpm 50907 a3e42cf0c917290c009adba1f404b5e4 php-mbstring-5.2.4-16.x86_64.rpm 2164973 a31def8817f7ef56d83eecdabd719f02 php-mcrypt-5.2.4-16.x86_64.rpm 38679 6ce49e923bfd34c4d3c4d85ddc1f9df0 php-mhash-5.2.4-16.x86_64.rpm 19956 8d8248ae180a2abc71b4391a0b3dda38 php-mssql-5.2.4-16.x86_64.rpm 54141 af01a3dc6e247d42eb337c9b1ee55f26 php-mysql-5.2.4-16.x86_64.rpm 156990 928d69722a95fc408fa0728dc27070e1 php-ncurses-5.2.4-16.x86_64.rpm 60573 4c624b74e3dc4bd9108cc9ad1eff433a php-odbc-5.2.4-16.x86_64.rpm 85277 bc3257026ec55177798a2c4bb32272ec php-pdo-5.2.4-16.x86_64.rpm 111510 cc744b01c0e5714f8f94419e1cac2599 php-pgsql-5.2.4-16.x86_64.rpm 122762 fb7f251f1f7bb601f5eca76631e0590d php-snmp-5.2.4-16.x86_64.rpm 31463 39baf7eb4fb36760fe514c035d3723b0 php-soap-5.2.4-16.x86_64.rpm 270624 edad391a77a7a0404a62782c84f7acb7 php-tidy-5.2.4-16.x86_64.rpm 46196 3b73165793d20ba1b740b1aa399b4d1f php-xml-5.2.4-16.x86_64.rpm 187194 028fe2521843a86abf2d3fa49a72995c php-xmlrpc-5.2.4-16.x86_64.rpm 89878 9bee1c5f63ee65a0e5e57af7b91e1fa2
<Turbolinux 11 Server>
Source Packages Size: MD5
php-5.2.4-16.src.rpm 7657424 d7d8e223224959fe02241b853a9ad9a1
Binary Packages Size: MD5
php-5.2.4-16.i686.rpm 3827984 c48ecf3cb16e43d7340f1cc7cf6db4d9 php-bcmath-5.2.4-16.i686.rpm 36065 70bead6d7250a0ce220ee1ecff1c1f30 php-cli-5.2.4-16.i686.rpm 2486167 e5e93cd519b4cfdc5b069fa010a8fb3c php-common-5.2.4-16.i686.rpm 272262 6ce74a9d0e4ecd8535ad97d7cec8e7c1 php-dba-5.2.4-16.i686.rpm 56406 42312114e1636bcc8c9ee8cf4ce35e84 php-devel-5.2.4-16.i686.rpm 570597 a92269bae905912003e768cf0b497b74 php-embedded-5.2.4-16.i686.rpm 1264892 1d356a7e80b857fe35f0eef49d179d86 php-gd-5.2.4-16.i686.rpm 200242 ac9c18e80144b9b98ef52c84fbc2ce03 php-imap-5.2.4-16.i686.rpm 79720 be3191dd7e0f54348eec0ffdc4de685e php-ldap-5.2.4-16.i686.rpm 46613 b297afa99e9168dd01d8abd4d9c4cd74 php-mbstring-5.2.4-16.i686.rpm 2123277 a4b7dcc58e6c6a154b159acc4ee3afc5 php-mcrypt-5.2.4-16.i686.rpm 33187 54bd7c7588775f5243b4b6479e188aed php-mhash-5.2.4-16.i686.rpm 19154 6e8cb0550487cc84081fd2a41078b4b0 php-mssql-5.2.4-16.i686.rpm 50704 3bc50b1a2d9139f08c8d02267667da9a php-mysql-5.2.4-16.i686.rpm 139741 db913fd436718d5bf17abc0e04a346d1 php-ncurses-5.2.4-16.i686.rpm 54232 a78a4623032f5d0b770073e5cb0bbab4 php-odbc-5.2.4-16.i686.rpm 77571 f40d3e4ed751e950a6ab236d9b7c6b61 php-pdo-5.2.4-16.i686.rpm 103221 d891b29078ebae5afc2764e3eaea1175 php-pgsql-5.2.4-16.i686.rpm 111215 a51fbd1eaa23305e41802baef101ad31 php-snmp-5.2.4-16.i686.rpm 29055 8fecc9bda8b45d635b863e9f53e3f62b php-soap-5.2.4-16.i686.rpm 266375 5856778ece30d4ed3be6e4e5734ee3f6 php-tidy-5.2.4-16.i686.rpm 42908 15236a0a3374d50d6682f656ee898302 php-xml-5.2.4-16.i686.rpm 164335 6338fd019bc303eff2197361f82e3816 php-xmlrpc-5.2.4-16.i686.rpm 83679 ea76d2cd504ecd0a76b23aa7c28511ca
<Turbolinux Appliance Server 2.0>
Source Packages Size: MD5
php4-4.3.11-28.src.rpm 12533633 054aa9d012c5aa736eeb025efd0ade2f
Binary Packages Size: MD5
php4-4.3.11-28.i586.rpm 5369505 bdeac48ba7705f14157ab2877164076e php4-gd-4.3.11-28.i586.rpm 50915 02d0e4e5acd35c3fc2030f6d202962fe php4-imap-4.3.11-28.i586.rpm 14155 bf4f188053279194344f1d57133d5f8b php4-ldap-4.3.11-28.i586.rpm 37510 f60bd5eb31c79b5204311493bf5f52b5 php4-manual-4.3.11-28.i586.rpm 7506024 f9648572996343de3f1990c4df61b20a php4-ming-4.3.11-28.i586.rpm 48940 90e1e96185a06edf7b5a0bbaf4713822 php4-mysql-4.3.11-28.i586.rpm 124849 8453982d97e12bfb6fb29cbcecab2541 php4-pgsql-4.3.11-28.i586.rpm 74105 06691c98599aaca0e65c062252b1104c
<Turbolinux 10 Server x64 Edition>
Source Packages Size: MD5
php4-4.3.9-19.src.rpm 12378926 2dfbf7d6bee42759bd598893e8acaf45
Binary Packages Size: MD5
php4-4.3.9-19.x86_64.rpm 5478708 0c9157f2bfa129560b0e8c548be3d5dd php4-debug-4.3.9-19.x86_64.rpm 6587192 6018e1d887d3cc7098420ebaf39d7ef4 php4-gd-4.3.9-19.x86_64.rpm 54251 f208056eec471094817f833664d3f4e5 php4-imap-4.3.9-19.x86_64.rpm 11989 92264575a09cf7c23c19debae6cee3e3 php4-ldap-4.3.9-19.x86_64.rpm 39824 661796717e33835e21633bedce8a4169 php4-manual-4.3.9-19.x86_64.rpm 7502602 224b9c22a046899249c120f1e0171f6d php4-ming-4.3.9-19.x86_64.rpm 51942 1f0ec3543ce2b75ecaa49f1aa7898c47 php4-mysql-4.3.9-19.x86_64.rpm 135222 aa257d2736d97c5f956a12c7e9a9701c php4-pgsql-4.3.9-19.x86_64.rpm 76873 0e2aacead26428dbc54d6061f4090dcf
<Turbolinux Appliance Server 1.0 Hosting Edition>
Source Packages Size: MD5
php-4.2.3-41.src.rpm 3618132 eec3666c565f0dd28f9a8a8fa2d8e5db
Binary Packages Size: MD5
php-4.2.3-41.i586.rpm 1635167 674cadc77fa15105276b2133707a9790 php-gd-4.2.3-41.i586.rpm 32802 daa552d63809a012ead44d2b7382ab4f php-imap-4.2.3-41.i586.rpm 10599 f6cae51d9cc6a05b8654edbebe58b308 php-ldap-4.2.3-41.i586.rpm 26013 41888d9956e415e71f0a0884167b5027 php-manual-4.2.3-41.i586.rpm 343115 ed3b79aef107ee215af4686c6ecd5429 php-ming-4.2.3-41.i586.rpm 34555 f4a521696a86c05866414d4baaf4ce8a php-mysql-4.2.3-41.i586.rpm 92157 f18f96d672876802d94f3ca65bb22e15 php-pgsql-4.2.3-41.i586.rpm 36799 21f0098d856e73effd4e1a0d244cce07
<Turbolinux Appliance Server 1.0 Workgroup Edition>
Source Packages Size: MD5
php-4.2.3-41.src.rpm 3618132 017ea9bf3a8007e7f03b8de4cf87e006
Binary Packages Size: MD5
php-4.2.3-41.i586.rpm 1635738 76684275a93bd4dc0bf6a58bcb9972b2 php-gd-4.2.3-41.i586.rpm 32974 ceb00ef18e88f20178ba408dab610226 php-imap-4.2.3-41.i586.rpm 10752 442600cb7b43185d874160515940f38c php-ldap-4.2.3-41.i586.rpm 26136 0c452034dfb3e4f11dd96461ecd16b5e php-manual-4.2.3-41.i586.rpm 343172 bc82bb6dab46ca95ee524bc57239d434 php-ming-4.2.3-41.i586.rpm 34727 07812f4e2fba0e66711fa31494ea2a2b php-mysql-4.2.3-41.i586.rpm 92340 c5d5320f0e16219b967ad17c7817d326 php-pgsql-4.2.3-41.i586.rpm 36972 0d47f3ec22727dcb522d97eb4acf4ef3
<Turbolinux 10 Server>
Source Packages Size: MD5
php4-4.3.11-28.src.rpm 12533633 054aa9d012c5aa736eeb025efd0ade2f
Binary Packages Size: MD5
php4-4.3.11-28.i586.rpm 5369505 bdeac48ba7705f14157ab2877164076e php4-debug-4.3.11-28.i586.rpm 6462829 0650ac3eaba7eb514ad968a35bac858f php4-gd-4.3.11-28.i586.rpm 50915 02d0e4e5acd35c3fc2030f6d202962fe php4-imap-4.3.11-28.i586.rpm 14155 bf4f188053279194344f1d57133d5f8b php4-ldap-4.3.11-28.i586.rpm 37510 f60bd5eb31c79b5204311493bf5f52b5 php4-manual-4.3.11-28.i586.rpm 7506024 f9648572996343de3f1990c4df61b20a php4-ming-4.3.11-28.i586.rpm 48940 90e1e96185a06edf7b5a0bbaf4713822 php4-mysql-4.3.11-28.i586.rpm 124849 8453982d97e12bfb6fb29cbcecab2541 php4-pgsql-4.3.11-28.i586.rpm 74105 06691c98599aaca0e65c062252b1104c
References:
CVE [CVE-2007-4782] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4782 [CVE-2007-4850] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4850 [CVE-2008-1384] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1384 [CVE-2008-2050] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2050 [CVE-2008-2051] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2051 [CVE-2008-3658] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3658 [CVE-2008-3659] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3659 [CVE-2008-3660] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3660 [CVE-2008-5498] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5498
-------------------------------------------------------------------------- Revision History 28 Jan 2009 Initial release --------------------------------------------------------------------------
Copyright(C) 2009 Turbolinux, Inc. All rights reserved.
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.10 (GNU/Linux)
iEYEARECAAYFAkl/2xQACgkQK0LzjOqIJMwgvACfagY+oOz5/oyj8FDYb4RotwOH 8jUAn3BdR9uV/gHr1XGw3Nl56G+kVx6r =oUFu -----END PGP SIGNATURE-----
|
|
|
|