Summary
The remote host is missing an update to php5
announced via advisory DSA 1444-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201444-1
Insight
Several remote vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-3799
It was discovered that the session_start() function allowed the insertion of attributes into the session cookie.
CVE-2007-3998
Mattias Bengtsson and Philip Olausson discovered that a programming error in the implementation of the wordwrap() function allowed denial of service through an infinite loop.
CVE-2007-4658
Stanislav Malyshev discovered that a format string vulnerability in the money_format() function could allow the execution of arbitrary code.
CVE-2007-4659
Stefan Esser discovered that execution control flow inside the zend_alter_ini_entry() function in handled incorrectly in case of a memory limit violation.
CVE-2007-4660
Gerhard Wagner discovered an integer overflow inside the chunk_split function().
CVE-2007-5898
Rasmus Lerdorf discovered that incorrect parsing of multibyte sequences may lead to disclosure of memory contents.
CVE-2007-5899
It was discovered that the output_add_rewrite_var() function could leak session ID information, resulting in information disclosure.
This update also fixes two bugs from in the PHP 5.2.4 release which don't have security impact according to the Debian PHP security policy (CVE-2007-4657 and CVE-2007-4662), but which are fixed nonetheless.
For the stable distribution (etch), these problems have been fixed in version 5.2.0-8+etch9.
The old stable distribution (sarge) doesn't contain php5.
For the unstable distribution (sid), these problems have been fixed in version 5.2.4-1, with the exception of CVE-2007-5898 and CVE-2007-5899, which will be fixed soon. Please note that Debian's version of PHP is hardened with the Suhosin patch beginning with version 5.2.4-1, which renders several vulnerabilities ineffective.
We recommend that you upgrade your php5 packages.
Severity
Classification
-
CVE CVE-2007-3799, CVE-2007-3998, CVE-2007-4657, CVE-2007-4658, CVE-2007-4659, CVE-2007-4660, CVE-2007-4662, CVE-2007-5898, CVE-2007-5899 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities