[Bug 813110] Re: CVE-2011-1938
Launchpad Bug Tracker
813110 at bugs.launchpad.net
Mon Oct 17 22:07:02 UTC 2011
This bug was fixed in the package php5 - 5.3.5-1ubuntu7.3
---------------
php5 (5.3.5-1ubuntu7.3) natty-security; urgency=low
[ Angel Abad ]
* SECURITY UPDATE: File path injection vulnerability in RFC1867 File
upload filename (LP: #813115)
- debian/patches/php5-CVE-2011-2202.patch:
- CVE-2011-2202
* SECURITY UPDATE: Fixed stack buffer overflow in socket_connect()
(LP: #813110)
- debian/patches/php5-CVE-2011-1938.patch:
- CVE-2011-1938
[ Steve Beattie ]
* SECURITY UPDATE: DoS in zip handling due to addGlob() crashing
on invalid flags
- debian/patches/php5-CVE-2011-1657.patch: check for valid flags
- CVE-2011-1657
* SECURITY UPDATE: crypt_blowfish doesn't properly handle 8-bit
(non-ascii) passwords leading to a smaller collision space
- debian/patches/php5-CVE-2011-2483.patch: update crypt_blowfish
to 1.2 to correct handling of passwords containing 8-bit
(non-ascii) characters.
CVE-2011-2483
* SECURITY UPDATE: DoS due to failure to check for memory allocation errors
- debian/patches/php5-CVE-2011-3182.patch: check the return values
of the malloc, calloc, and realloc functions
- CVE-2011-3182
* SECURITY UPDATE: DoS in errorlog() when passed NULL
- debian/patches/php5-CVE-2011-3267.patch: fix NULL pointer crash in
errorlog()
- CVE-2011-3267
* debian/patches/fix_crash_in__php_mssql_get_column_content_without_type.patch:
refresh patch to make it cleanly apply.
-- Steve Beattie <sbeattie at ubuntu.com> Thu, 13 Oct 2011 13:49:23 -0700
** Changed in: php5 (Ubuntu Natty)
Status: In Progress => Fix Released
** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2011-1657
** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2011-2202
** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2011-2483
** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2011-3182
** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2011-3267
** Changed in: php5 (Ubuntu Maverick)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to php5 in Ubuntu.
https://bugs.launchpad.net/bugs/813110
Title:
CVE-2011-1938
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/php5/+bug/813110/+subscriptions
More information about the Ubuntu-server-bugs
mailing list