Summary
The remote host is missing updates announced in
advisory GLSA 201209-03.
Solution
All PHP users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=dev-lang/php-5.3.15'
All PHP users on ARM should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=dev-lang/php-5.4.5'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20201209-03 http://bugs.gentoo.org/show_bug.cgi?id=384301
http://bugs.gentoo.org/show_bug.cgi?id=396311
http://bugs.gentoo.org/show_bug.cgi?id=396533
http://bugs.gentoo.org/show_bug.cgi?id=399247
http://bugs.gentoo.org/show_bug.cgi?id=399567
http://bugs.gentoo.org/show_bug.cgi?id=399573
http://bugs.gentoo.org/show_bug.cgi?id=401997
http://bugs.gentoo.org/show_bug.cgi?id=410957
http://bugs.gentoo.org/show_bug.cgi?id=414553
http://bugs.gentoo.org/show_bug.cgi?id=421489
http://bugs.gentoo.org/show_bug.cgi?id=427354
http://bugs.gentoo.org/show_bug.cgi?id=429630
Insight
Multiple vulnerabilities were found in PHP, the worst of which lead to remote execution of arbitrary code.
Severity
Classification
-
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities