Jump to content

Advisories MDKSA-2006:162: Updated php packages fix vulnerabilities


paul
 Share

Recommended Posts

The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5

do not check for the safe_mode and open_basedir settings, which allows

local users to bypass the settings (CVE-2006-4481).

 

Buffer overflow in the LWZReadByte function in ext/gd/libgd/gd_gif_in.c

in the GD extension in PHP before 5.1.5 allows remote attackers to have

an unknown impact via a GIF file with input_code_size greater than

MAX_LWZ_BITS, which triggers an overflow when initializing the table

array (CVE-2006-4484).

 

The stripos function in PHP before 5.1.5 has unknown impact and attack

vectors related to an out-of-bounds read (CVE-2006-4485).

 

CVE-2006-4485 does not affect the Corporate3 or MNF2 versions of PHP.

 

Updated packages have been patched to correct these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...