Secunia Logo  
 
Gentoo update for php
Secunia Advisory: SA32746
Release Date: 2008-11-17
Popularity: 590 views

Critical:
Moderately critical
Impact: Unknown
Security Bypass
Exposure of sensitive information
DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:Gentoo Linux 1.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2008-0599
CVE-2008-0674
CVE-2008-1384
CVE-2008-2050
CVE-2008-2051
CVE-2008-2107
CVE-2008-2108
CVE-2008-2371
CVE-2008-2665
CVE-2008-2666
CVE-2008-2829
CVE-2008-3658
CVE-2008-3659
CVE-2008-3660


Description:
Gentoo has issued an update for php. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions, and potentially by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or to compromise a vulnerable system.

For more information:
SA28923
SA30048
SA30916
SA31409

Solution:
Update to "dev-lang/php-5.2.6-r6" or later.

Original Advisory:
GLSA-200811-05:
http://www.gentoo.org/security/en/glsa/glsa-200811-05.xml

Other References:
SA28923:
http://secunia.com/advisories/28923/

SA30048:
http://secunia.com/advisories/30048/

SA30916:
http://secunia.com/advisories/30916/

SA31409:
http://secunia.com/advisories/31409/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. NTP OpenSSL "EVP_VerifyFinal()" Spoofing Vulnerability // 44 views
2. Drupal Project Module File Upload and Cross-Site Scripting // 41 views
3. phpBB reveals user IPs // 40 views
4. Cisco Global Site Selector DNS Request Denial of Service // 37 views
5. SmbFTPD Long Command Processing Vulnerability // 36 views
6. Red Hat update for openssl // 36 views
7. Lasso OpenSSL "DSA_verify()" Spoofing Vulnerability // 35 views
8. FreeBSD update for openssl // 33 views
9. ISC BIND "EVP_VerifyFinal()" and "DSA_do_verify()" Spoofing Vulnerability // 32 views
10. Drupal Project Issue Tracking Module Multiple Vulnerabilities // 31 views