[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2639-1 php5 -- several

ID: oval:org.secpod.oval:def:600983Date: (C)2013-03-08   (M)2023-12-07
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in PHP, the web scripting language. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-1635 If a PHP application accepted untrusted SOAP object input remotely from clients, an attacker could read system files readable for the webserver. CVE-2013-1643 The soap.wsdl_cache_dir function did not take PHP open_basedir restrictions into account. Note that Debian advises against relying on open_basedir restrictions for security.

Platform:
Debian 6.0
Product:
php5
Reference:
DSA-2639-1
CVE-2013-1635
CVE-2013-1643
CVE    2
CVE-2013-1643
CVE-2013-1635
CPE    139
cpe:/a:php:php:3.0
cpe:/a:php:php:5.0.0:rc3
cpe:/a:php:php:5.0.0:rc2
cpe:/a:php:php:5.0.0:rc1
...

© SecPod Technologies