Summary
The remote host is missing an update as announced
via advisory SSA:2007-152-01.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=SSA:2007-152-01
Insight
New php5 packages are available for Slackware 10.2, 11.0, and -current to fix security issues. PHP5 was considered a test package in Slackware 10.2, and an 'extra' package in Slackware 11.0. If you are currently running PHP4 you may wish to stick with that, as upgrading to PHP5 will probably require changes to your system's configuration and/or web code.
More details about the issues affecting Slackware's PHP5 may be found in the Common Vulnerabilities and Exposures (CVE) database:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1900 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2756 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2872
One CVE-issued vulnerability (CVE-2007-1887) does not affect Slackware as we do not ship an unbundled sqlite2 library.
Severity
Classification
-
CVE CVE-2007-1887, CVE-2007-1900, CVE-2007-2756, CVE-2007-2872 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities