Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in PHP
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in PHP
ID: USN-1702-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS
Datum: Di, 22. Januar 2013, 17:35
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6113
Applikationen: PHP

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--===============3662774625078209997==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="------------enig92D78B8AF25110413FF030CC"

This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig92D78B8AF25110413FF030CC
Content-Type: text/plain; charset=ISO-8859-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1702-1
January 22, 2013

php5 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

PHP could be made to expose sensitive information over the network.

Software Description:
- php5: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP incorrectly handled the openssl_encrypt function
when used with an empty string. An attacker could use this flaw to cause
PHP to disclose arbitrary memory contents and possibly expose sensitive
information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
php5 5.3.10-1ubuntu3.5

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1702-1
CVE-2012-6113

Package Information:
https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.5



--------------enig92D78B8AF25110413FF030CC
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCgAGBQJQ/pR5AAoJEGVp2FWnRL6TyEAQAIf2kw9KCyMKrNKyyl3HHhq/
ffOxs8khldC7GhmsC/mAlhs5GPBpSNEwdMLQSNd7JbftnRTCCn5VlafMZol3+LSP
+43S6/v/JpEXsB0FMk/s1A4h5+/vn3i79i7o/U5eKpjfNdvUdmsC4MldGiI+0zvy
TJXGmyKpCCHt6loh9mLKy/nZO0XVhsCT2QtQWRcPSRkVeoXhQXvNXE24Y3xxrMHV
liTctmDHOQcdRn/LduP0OWJbpm/Ifi/5PPgL3CZHlfzfYx4FkgtyjIt1NopuglTz
+IOAZ62sLa1ZJUMa3hOkD1Ntr3s9nr7ubY91xQpHdaFp3yYKWGoDLOAVI/pFhSCj
xMqbwMP4NxvUGnAkO2DiorkQenx2PF8rX0PaCFashYvZ01KpSQXtwpQZYZAleTo8
mXn6AQR+0pz6ALUEAaNH9BC4HmbbVKfHCsdbcgGnJ7hzwwSsCPKWP1YiqHumZHnI
x43yzBQbgkoc10wNAh67+KbrbU5aPkvhtN6uX8T/JSWaB/o6UlOGebgy6ULLDM2C
FIEjK0nL4lBQ3ixr4lGGxWoBCpqw6XGwl9V8CjM9EebYUdmViH9+165vVRigrnld
eyQceuiQyFD+w0XFcm8GUvAXgry5cya8xoyIZaMds7iq4br7VP8vFXrWkHNMlWl9
tILRUI2sc60kSbTWKSib
=Pt2H
-----END PGP SIGNATURE-----

--------------enig92D78B8AF25110413FF030CC--


--===============3662774625078209997==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============3662774625078209997==--
Pro-Linux
Gewinnspiel
Neue Nachrichten
Werbung