[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2010:008 -- Mandriva php

ID: oval:org.secpod.oval:def:300384Date: (C)2012-01-07   (M)2024-02-19
Class: PATCHFamily: unix




Multiple vulnerabilities has been found and corrected in php: The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable . The htmlspecialchars function in PHP before 5.2.12 does not properly handle overlong UTF-8 sequences, invalid Shift_JIS sequences, and invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting attacks by placing a crafted byte sequence before a special character . Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct these issues.

Platform:
Mandriva Linux 2009.0
Mandriva Linux 2008.0
Product:
php
Reference:
MDVSA-2010:008
CVE-2009-4142
CVE-2009-2626
CVE    2
CVE-2009-4142
CVE-2009-2626
CPE    2
cpe:/o:mandriva:linux:2009.0
cpe:/o:mandriva:linux:2008.0

© SecPod Technologies