Ubuntu PHP5 vulnerabilities
- vulnerability |
- ubuntu |
- security |
- PHP |
- exploit
Secunia Advisory: SA33939
Verification: http://secunia.com/advisories/33939/
Critical: Moderately critical
| Impact: |
Security Bypass DoS System access |
|
| Where: | From remote | |
| Solution Status: | Vendor Patch | |
| OS: |
Ubuntu Linux 6.06 Ubuntu Linux 7.10 Ubuntu Linux 8.04 Ubuntu Linux 8.10 |
|
Description:
Ubuntu has issued an update for php5. This fixes some vulnerabilities, which can be exploited by malicious users to bypass certain security restrictions, and by malicious people to cause a DoS (Denial of Service) or potentially to compromise a vulnerable system.
For more information:
SA26642
SA27648
SA31409
SA32964
USN-557-1 fixed a vulnerability in the GD library. PHP did not properly handle the return codes that were added in the security update. This can be exploited to cause PHP to crash via a specially crafted image file. This issue only applies to Ubuntu 6.06 LTS and 7.10.



