[ubuntu/precise-security] php5 5.3.10-1ubuntu3.4 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Mon Sep 17 12:14:38 UTC 2012
php5 (5.3.10-1ubuntu3.4) precise-security; urgency=low
* SECURITY UPDATE: HTTP response-splitting issue with %0D sequences
- debian/patches/CVE-2011-1398.patch: properly handle %0D and NUL in
main/SAPI.c, added tests to ext/standard/tests/*, fix test suite
failures in ext/phar/phar_object.c.
- CVE-2011-1398
- CVE-2012-4388
* SECURITY UPDATE: denial of service and possible code execution via
_php_stream_scandir function (LP: #1028064)
- debian/patches/CVE-2012-2688.patch: prevent overflow in
main/streams/streams.c.
- CVE-2012-2688
* SECURITY UPDATE: denial of service via PDO extension crafted parameter
- debian/patches/CVE-2012-3450.patch: improve logic in
ext/pdo/pdo_sql_parser.re, regenerate ext/pdo/pdo_sql_parser.c, add
test to ext/pdo_mysql/tests/bug_61755.phpt.
- CVE-2012-3450
php5 (5.3.10-1ubuntu3.3) precise-proposed; urgency=low
* Applies upstream bug fixes for several issues and bugs:
* php5-fpm segfaults with error 4 in libc-2.15.so
(LP: #1006738. Bug Priority: High)
* PHP5-FPM not reporting errors to web server (nginx)
(LP: #1014044. Bug Priority: Medium)
Date: 2012-09-12 18:30:11.958388+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/precise/+source/php5/5.3.10-1ubuntu3.4
-------------- next part --------------
Sorry, changesfile not available.
More information about the Precise-changes
mailing list