Description: | Description:
The remote host is missing an update to php announced via advisory FEDORA-2008-3864.
Update Information:
This release updates PHP to the latest upstream version 5.2.6, fixing multiple bugs and security issues. For more details, please visit the referenced security advisories.
ChangeLog:
* Thu May 8 2008 Joe Orton 5.2.6-2 - update to 5.2.6 * Wed Apr 2 2008 Joe Orton 5.2.5-4 - rebuild for new uw-imap * Wed Feb 13 2008 Joe Orton 5.2.5-3 - ext/date: use system timezone database * Tue Dec 11 2007 Joe Orton 5.2.5-1 - update to 5.2.5 (#384991)
References:
[ 1 ] Bug #445685 - CVE-2008-2108 PHP weak 64 bit random seed https://bugzilla.redhat.com/show_bug.cgi?id=445685 [ 2 ] Bug #382431 - CVE-2007-5899 php session ID leakage https://bugzilla.redhat.com/show_bug.cgi?id=382431 [ 3 ] Bug #285881 - CVE-2007-4782 php crash in glob() and fnmatch() functions https://bugzilla.redhat.com/show_bug.cgi?id=285881 [ 4 ] Bug #445003 - CVE-2008-0599 php: buffer overflow in a CGI path translation https://bugzilla.redhat.com/show_bug.cgi?id=445003 [ 5 ] Bug #445006 - CVE-2008-2051 PHP multibyte shell escape flaw https://bugzilla.redhat.com/show_bug.cgi?id=445006 [ 6 ] Bug #382411 - CVE-2007-5898 php htmlentities/htmlspecialchars multibyte sequences https://bugzilla.redhat.com/show_bug.cgi?id=382411 [ 7 ] Bug #445684 - CVE-2008-2107 PHP 32 bit weak random seed https://bugzilla.redhat.com/show_bug.cgi?id=445684
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update php' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-3864
Risk factor : Critical
CVSS Score: 10.0
|