Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.841151
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-1569-1)
Summary:The remote host is missing an update for the 'php5' package(s) announced via the USN-1569-1 advisory.
Description:Summary:
The remote host is missing an update for the 'php5' package(s) announced via the USN-1569-1 advisory.

Vulnerability Insight:
It was discovered that PHP incorrectly handled certain character sequences
when applying HTTP response-splitting protection. A remote attacker could
create a specially-crafted URL and inject arbitrary headers.
(CVE-2011-1398, CVE-2012-4388)

It was discovered that PHP incorrectly handled directories with a large
number of files. This could allow a remote attacker to execute arbitrary
code with the privileges of the web server, or to perform a denial of
service. (CVE-2012-2688)

It was discovered that PHP incorrectly parsed certain PDO prepared
statements. A remote attacker could use this flaw to cause PHP to crash,
leading to a denial of service. (CVE-2012-3450)

Affected Software/OS:
'php5' package(s) on Ubuntu 8.04, Ubuntu 10.04, Ubuntu 11.04, Ubuntu 11.10, Ubuntu 12.04.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-1398
https://bugs.php.net/bug.php?id=60227
http://article.gmane.org/gmane.comp.php.devel/70584
http://openwall.com/lists/oss-security/2012/08/29/5
http://openwall.com/lists/oss-security/2012/09/05/15
RedHat Security Advisories: RHSA-2013:1307
http://rhn.redhat.com/errata/RHSA-2013-1307.html
http://www.securitytracker.com/id?1027463
http://secunia.com/advisories/55078
SuSE Security Announcement: SUSE-SU-2013:1315 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.html
http://www.ubuntu.com/usn/USN-1569-1
Common Vulnerability Exposure (CVE) ID: CVE-2012-2688
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
BugTraq ID: 54638
http://www.securityfocus.com/bid/54638
Debian Security Information: DSA-2527 (Google Search)
http://www.debian.org/security/2012/dsa-2527
http://www.mandriva.com/security/advisories?name=MDVSA-2012:108
http://www.securitytracker.com/id?1027287
SuSE Security Announcement: SUSE-SU-2012:1033 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00021.html
SuSE Security Announcement: SUSE-SU-2012:1034 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00022.html
SuSE Security Announcement: openSUSE-SU-2012:0976 (Google Search)
https://hermes.opensuse.org/messages/15376003
XForce ISS Database: php-phpstreamscandir-unspecified(77155)
https://exchange.xforce.ibmcloud.com/vulnerabilities/77155
Common Vulnerability Exposure (CVE) ID: CVE-2012-3450
20120610 [php<=5.4.3] Parsing Bug in PHP PDO prepared statements may lead to access violation
http://seclists.org/bugtraq/2012/Jun/60
DSA-2527
MDVSA-2012:108
SUSE-SU-2012:1033
USN-1569-1
[oss-security] 20120802 CVE Request: php5 pdo array overread/crash
http://www.openwall.com/lists/oss-security/2012/08/02/3
[oss-security] 20120802 Re: CVE Request: php5 pdo array overread/crash
http://www.openwall.com/lists/oss-security/2012/08/02/7
http://www.php.net/ChangeLog-5.php
https://bugs.php.net/bug.php?id=61755
https://bugzilla.novell.com/show_bug.cgi?id=769785
Common Vulnerability Exposure (CVE) ID: CVE-2012-4388
1027463
SUSE-SU-2013:1315
[internals] 20120203 [PHP-DEV] The case of HTTP response splitting protection in PHP
[oss-security] 20120829 php header() header injection detection bypass
[oss-security] 20120901 Re: php header() header injection detection bypass
http://openwall.com/lists/oss-security/2012/09/02/1
[oss-security] 20120905 Re: php header() header injection detection bypass
[oss-security] 20120906 Re: Re: php header() header injection detection bypass
http://openwall.com/lists/oss-security/2012/09/07/3
http://security-tracker.debian.org/tracker/CVE-2012-4388
http://svn.php.net/viewvc/php/php-src/branches/PHP_5_4/main/SAPI.c?r1=323986&r2=323985&pathrev=323986
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.