Login
Newsletter
Werbung

Sicherheit: Pufferüberlauf in php-apc
Aktuelle Meldungen Distributionen
Name: Pufferüberlauf in php-apc
ID: MDVSA-2008:082
Distribution: Mandriva
Plattformen: Mandriva Corporate 4.0
Datum: Sa, 12. April 2008, 18:06
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1488
Applikationen: php-apc

Originalnachricht

This is a multi-part message in MIME format...

------------=_1208016385-11275-2430


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2008:082
http://www.mandriva.com/security/
_______________________________________________________________________

Package : php-apc
Date : April 9, 2008
Affected: Corporate 4.0
_______________________________________________________________________

Problem Description:

Daniel Papasian discovered a stack-based buffer overflow in the
apc_search_paths() function in APC that can be triggered when
processing long filenames. A remote attacker could exploit this
vulnerability to execute arbitrarty code in PHP applications that
pass user-controlled input to the include() function.

The updated packages have been patched to correct these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1488
_______________________________________________________________________

Updated Packages:

Corporate 4.0:
f8a3b00e540d1227a01859a0eb5b8308
corporate/4.0/i586/php4-apc-3.0.11-1.1.20060mlcs4.i586.rpm
f515e731577e4848c5442a39cfec3bb3
corporate/4.0/i586/php4-apc-admin-3.0.11-1.1.20060mlcs4.i586.rpm
a3d785f83389bfd7a06e1c7c7ff1e0ba
corporate/4.0/i586/php-apc-3.0.11-2.1.20060mlcs4.i586.rpm
7dc5b581c14fcca3c6c4bb07b93a0370
corporate/4.0/i586/php-apc-admin-3.0.11-2.1.20060mlcs4.i586.rpm
90c85cef2bc50c175cad42f80aefd116
corporate/4.0/SRPMS/php4-apc-3.0.11-1.1.20060mlcs4.src.rpm
90ce6133b0964a41b8b2fd7880af84e0
corporate/4.0/SRPMS/php-apc-3.0.11-2.1.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
4d58c491a9cc42cde58f519f35794c8f
corporate/4.0/x86_64/php4-apc-3.0.11-1.1.20060mlcs4.x86_64.rpm
3f53d18d2c29d88aa7e1c5ccf45d255f
corporate/4.0/x86_64/php4-apc-admin-3.0.11-1.1.20060mlcs4.x86_64.rpm
468eb332b10101d0051af4696c6b4f6f
corporate/4.0/x86_64/php-apc-3.0.11-2.1.20060mlcs4.x86_64.rpm
3be0fb797e4eb676d6374a26463e6541
corporate/4.0/x86_64/php-apc-admin-3.0.11-2.1.20060mlcs4.x86_64.rpm
90c85cef2bc50c175cad42f80aefd116
corporate/4.0/SRPMS/php4-apc-3.0.11-1.1.20060mlcs4.src.rpm
90ce6133b0964a41b8b2fd7880af84e0
corporate/4.0/SRPMS/php-apc-3.0.11-2.1.20060mlcs4.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iD8DBQFH/PB/mqjQ0CJFipgRArDpAKDtSYPWxX8DZ9U8zRYztNFHGMKbJQCffMBZ
gQ3jEezVode0XFvjaw2wKQc=
=gUHx
-----END PGP SIGNATURE-----


------------=_1208016385-11275-2430
Content-Type: text/plain; name="message-footer.txt"
Content-Disposition: inline; filename="message-footer.txt"
Content-Transfer-Encoding: 8bit

To unsubscribe, send a email to sympa@mandrivalinux.org
with this subject : unsubscribe security-announce
_______________________________________________________
Want to buy your Pack or Services from Mandriva?
Go to http://www.mandrivastore.com
Join the Club : http://www.mandrivaclub.com
_______________________________________________________

------------=_1208016385-11275-2430--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung