Description: | Description:
The remote host is missing updates announced in advisory TSLSA-2006-0055.
openldap < TSL 3.0 > < TSL 2.2 > < TSEL 2 > - SECURITY Fix: Howard Chu has reported a security issue in OpenLDAP, caused due to an error within the Access Control List processing. If a user has selfwrite access to an attribute, this can be exploited to modify arbitrary values of the attribute.
The Common Vulnerabilities and Exposures project has assigned the name CVE-2006-4600 to this issue.
php < TSL 3.0 > < TSL 2.2 > - SECURITY Fix: A vulnerability has been reported in PHP, caused due to an integer overflow within the _ecalloc function. This can potentially be exploited to execute arbitrary code via specially crafted requests if a PHP script allocates memory based on attacker supplied data.
The Common Vulnerabilities and Exposures project has assigned the name CVE-2006-4812 to this issue.
php4 < TSL 2.2 > - SECURITY Fix: A vulnerability has been reported in PHP, caused due to an integer overflow within the _ecalloc function. This can potentially be exploited to execute arbitrary code via specially crafted requests if a PHP script allocates memory based on attacker supplied data.
The Common Vulnerabilities and Exposures project has assigned the name CVE-2006-4812 to this issue.
Solution: Update your system with the packages as indicated in the referenced security advisory.
http://www.securityspace.com/smysecure/catid.html?in=TSLSA-2006-0055
Risk factor : Critical
CVSS Score: 10.0
|