Summary
The remote host is missing updates announced in
advisory GLSA 200703-21.
Solution
All PHP users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose 'dev-lang/php'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200703-21 http://bugs.gentoo.org/show_bug.cgi?id=153911
http://www.php.net/releases/4_4_5.php
http://www.php.net/releases/5_2_1.php
Insight
PHP contains several vulnerabilities including a heap buffer overflow, potentially leading to the remote execution of arbitrary code under certain conditions.
Severity
Classification
-
CVE CVE-2006-5465, CVE-2007-0906, CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0911, CVE-2007-0988, CVE-2007-1286, CVE-2007-1375, CVE-2007-1376, CVE-2007-1380, CVE-2007-1383 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities