php5 5.1.6-1ubuntu2.7 source package in Ubuntu
Changelog
php5 (5.1.6-1ubuntu2.7) edgy-security; urgency=low * SECURITY UPDATE: multiple vulnerabilities. Thanks to Sean Finney for help locating upstream fixes. * Add 200-string-wordwrap.patch: wordwrap function can be made to crash. Backported upstream fixes (CVE-2007-3998). * Add 201-strspn-oob-read.patch: memory reading, possible crash via strspn. chunk_split. Backported upstream fixes (CVE-2007-4657). * Add 202-money-format-abuse.patch: money_format format string vulnerable. Backported upstream fixes (CVE-2007-4658). * Add 203-openssl_make_REQ-overflow.patch: overflow in openssl_make_REQ. Applied and corrected upstream fixes (CVE-2007-4662). * Add 204-start-session-cookies.patch: overwrite cookie values. Applied upstream fixes (CVE-2007-3799). * Add 206-chunk_split-fixes.patch: memory reading, possible crash via chunk_split. Merged various upstream fixes (CVE-2007-2872, CVE-2007-4660, CVE-2007-4661). * Add 206-cookie-nesting-fix.patch: corruption/crashes via deeply nested variables. Backported upstream fixes (CVE-2007-1285, CVE-2007-4670). * Add 207-htmlentity-utf8-fix.patch: don't accept partial utf8 sequences. Backported upstream fixes (CVE-2007-5898). * Add 208-session-id-leak.patch: don't send session id to remote forms. Backported upstream fixes (CVE-2007-5899). * References http://www.php.net/releases/5_2_4.php http://www.php.net/releases/5_2_5.php -- Kees Cook <email address hidden> Fri, 19 Oct 2007 12:58:34 -0700
Upload details
- Uploaded by:
- Kees Cook
- Uploaded to:
- Edgy
- Original maintainer:
- Debian PHP Maintainers
- Architectures:
- any
- Section:
- web
- Urgency:
- Low Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
php5_5.1.6.orig.tar.gz | 7.8 MiB | 5c7963ff5915c15b10ab9cfab48976c55fa45955161519a61bc885ef89a335a5 |
php5_5.1.6-1ubuntu2.7.diff.gz | 114.2 KiB | 8ff1087e58f46384d9bcfc631420dee2bec5c08b0c79f8cfe27e8236fdde85c8 |
php5_5.1.6-1ubuntu2.7.dsc | 1.7 KiB | 9ff4dd40e140266563bb29e8958161059c23ae2fb2a59fa7a2f6f8e9acd6dd53 |
Binary packages built by this source
- libapache2-mod-php5: No summary available for libapache2-mod-php5 in ubuntu edgy.
No description available for libapache2-mod-php5 in ubuntu edgy.
- php-pear: No summary available for php-pear in ubuntu edgy.
No description available for php-pear in ubuntu edgy.
- php5: No summary available for php5 in ubuntu edgy.
No description available for php5 in ubuntu edgy.
- php5-cgi: No summary available for php5-cgi in ubuntu edgy.
No description available for php5-cgi in ubuntu edgy.
- php5-cli: No summary available for php5-cli in ubuntu edgy.
No description available for php5-cli in ubuntu edgy.
- php5-common: No summary available for php5-common in ubuntu edgy.
No description available for php5-common in ubuntu edgy.
- php5-curl: No summary available for php5-curl in ubuntu edgy.
No description available for php5-curl in ubuntu edgy.
- php5-dev: No summary available for php5-dev in ubuntu edgy.
No description available for php5-dev in ubuntu edgy.
- php5-gd: No summary available for php5-gd in ubuntu edgy.
No description available for php5-gd in ubuntu edgy.
- php5-ldap: No summary available for php5-ldap in ubuntu edgy.
No description available for php5-ldap in ubuntu edgy.
- php5-mhash: No summary available for php5-mhash in ubuntu edgy.
No description available for php5-mhash in ubuntu edgy.
- php5-mysql: No summary available for php5-mysql in ubuntu edgy.
No description available for php5-mysql in ubuntu edgy.
- php5-mysqli: No summary available for php5-mysqli in ubuntu edgy.
No description available for php5-mysqli in ubuntu edgy.
- php5-odbc: No summary available for php5-odbc in ubuntu edgy.
No description available for php5-odbc in ubuntu edgy.
- php5-pgsql: No summary available for php5-pgsql in ubuntu edgy.
No description available for php5-pgsql in ubuntu edgy.
- php5-recode: No summary available for php5-recode in ubuntu edgy.
No description available for php5-recode in ubuntu edgy.
- php5-snmp: No summary available for php5-snmp in ubuntu edgy.
No description available for php5-snmp in ubuntu edgy.
- php5-sqlite: No summary available for php5-sqlite in ubuntu edgy.
No description available for php5-sqlite in ubuntu edgy.
- php5-sybase: No summary available for php5-sybase in ubuntu edgy.
No description available for php5-sybase in ubuntu edgy.
- php5-xmlrpc: No summary available for php5-xmlrpc in ubuntu edgy.
No description available for php5-xmlrpc in ubuntu edgy.
- php5-xsl: No summary available for php5-xsl in ubuntu edgy.
No description available for php5-xsl in ubuntu edgy.