Jump to content

Advisories MDKSA-2007:103: Updated php packages fix multiple vulnerabilities


Recommended Posts

A heap buffer overflow flaw was found in the xmlrpc extension for PHP.

A script that implements an XML-RPC server using this extension could

allow a remote attacker to execute arbitrary code as the apache user.

This flaw does not, however, affect PHP applications using the pure-PHP

XML_RPC class provided via PEAR (CVE-2007-1864).

 

A flaw was found in the ftp extension for PHP. A script using

this extension to provide access to a private FTP server and which

passed untrusted script input directly to any function provided by

this extension could allow a remote attacker to send arbitrary FTP

commands to the server (CVE-2007-2509).

 

Updated packages have been patched to prevent this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...