Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Linux All distros and thier applications

Reply
 
Thread Tools Display Modes
  #1  
Old 10-23-2006, 08:43 AM
Mandriva's Avatar
Mandriva Mandriva is offline
Senior Member
 
Join Date: Oct 2006
Posts: 720
Mandriva- Advisories MDKSA-2006:185: Updated php packages to address multiple vulnerabilities

Advisories MDKSA-2006:185: Updated php packages to address multiple vulnerabilities
PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass
certain Apache HTTP Server httpd.conf options, such as safe_mode and
open_basedir, via the ini_restore function, which resets the values to
their php.ini (Master Value) defaults. (CVE-2006-4625)

A race condition in the symlink function in PHP 5.1.6 and earlier
allows local users to bypass the open_basedir restriction by using a
combination of symlink, mkdir, and unlink functions to change the file
path after the open_basedir check and before the file is opened by the
underlying system, as demonstrated by symlinking a symlink into a
subdirectory, to point to a parent directory via .. (dot dot)
sequences, and then unlinking the resulting symlink. (CVE-2006-5178)

Because the design flaw cannot be solved it is strongly recommended to
disable the symlink() function if you are using the open_basedir
feature. You can achieve that by adding symlink to the list of disabled
functions within your php.ini: disable_functions=...,symlink

The updated packages do not alter the system php.ini.

Updated packages have been patched to correct the CVE-2006-4625 issue.
Users must restart Apache for the changes to take effect.
http://mandrivausers.org/index.php?showtopic=36000
Array
Tue, 17 Oct 2006 23:06:28 +0000
Reply With Quote
Posted


Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump



All times are GMT -5. The time now is 05:57 AM.


Firefox 2