PHP Group Exif Module IFD Tag Integer Overflow Vulnerability
BID:13163
Info
PHP Group Exif Module IFD Tag Integer Overflow Vulnerability
| Bugtraq ID: | 13163 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-1042 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2005 12:00AM |
| Updated: | Jul 12 2009 12:56PM |
| Credit: | This issue was announced by the PHP Group. |
| Vulnerable: |
SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 SuSE Linux 7.3 sparc SuSE Linux 7.3 ppc SuSE Linux 7.3 i386 SuSE Linux 7.3 SuSE Linux 7.2 i386 SuSE Linux 7.2 SuSE Linux 7.1 x86 SuSE Linux 7.1 sparc SuSE Linux 7.1 ppc SuSE Linux 7.1 alpha SuSE Linux 7.1 SuSE Linux 7.0 sparc SuSE Linux 7.0 ppc SuSE Linux 7.0 i386 SuSE Linux 7.0 alpha SuSE Linux 7.0 SuSE Linux 6.4 ppc SuSE Linux 6.4 i386 SuSE Linux 6.4 alpha SuSE Linux 6.4 SuSE Linux 6.3 ppc SuSE Linux 6.3 alpha SuSE Linux 6.3 SuSE Linux 6.2 SuSE Linux 6.1 alpha SuSE Linux 6.1 SuSE Linux 6.0 SuSE Linux 5.3 SuSE Linux 5.2 SuSE Linux 5.1 SuSE Linux 5.0 SuSE Linux 4.4.1 SuSE Linux 4.4 SuSE Linux 4.3 SuSE Linux 4.2 SuSE Linux 4.0 SuSE Linux 3.0 SuSE Linux 2.0 SuSE Linux 1.0 SGI ProPack 3.0 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core2 Redhat Fedora Core1 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 Peachtree Linux release 1 Avaya S8710 R2.0.1 Avaya S8710 R2.0.0 Avaya S8700 R2.0.1 Avaya S8700 R2.0.0 Avaya S8500 R2.0.1 Avaya S8500 R2.0.0 Avaya S8300 R2.0.1 Avaya S8300 R2.0.0 Avaya Modular Messaging (MSS) 2.0 Avaya Modular Messaging (MSS) 1.1 Avaya MN100 Avaya Intuity LX Avaya Converged Communications Server 2.0 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 |
| Not Vulnerable: |
PHP PHP 4.3.11 |
Discussion
PHP Group Exif Module IFD Tag Integer Overflow Vulnerability
PHP is prone to an integer overflow vulnerability in the EXIF module. This issue is exposed when malformed IFD (Image File Directory) tags are processed.
This issue could manifest itself in Web applications that allow users to upload images. Any other application that processes untrusted EXIF image data could also be exposed to attacks. Successful exploitation may allow for execution of arbitrary code.
This vulnerability may be one of the issues described in BID 13143 "PHP Group PHP Multiple Unspecified Vulnerabilities".
PHP is prone to an integer overflow vulnerability in the EXIF module. This issue is exposed when malformed IFD (Image File Directory) tags are processed.
This issue could manifest itself in Web applications that allow users to upload images. Any other application that processes untrusted EXIF image data could also be exposed to attacks. Successful exploitation may allow for execution of arbitrary code.
This vulnerability may be one of the issues described in BID 13143 "PHP Group PHP Multiple Unspecified Vulnerabilities".
Exploit / POC
PHP Group Exif Module IFD Tag Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PHP Group Exif Module IFD Tag Integer Overflow Vulnerability
Solution:
Avaya has released an advisory (ASA-2005-136) that acknowledges this vulnerability for Avaya products. Please see the referenced Avaya advisory for further details.
Conectiva has released an advisory (CLSA-2005:955) and fixes to address this and other issues. Please see the referenced advisory for further information regarding obtaining and applying appropriate updates.
Turbolinux has released advisory TLSA-2005-50 along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
Peachtree Linux has released an advisory (PLSN-0001) including updated packages to address this issue. Please see the referenced advisory for more information.
Ubuntu has released advisory USN-112-1 to provide fixes for this issue. Please see the attached advisory for further information on obtaining and applying fixes.
This issue has been addressed in PHP 4.3.11.
Gentoo Linux has released advisory GLSA 200504-15 dealing with this issue. Gentoo advises that all users upgrade their packages by executing the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-php/php-4.3.11"
All mod_php users should upgrade to the latest version:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-php/mod_php-4.3.11"
All php-cgi users should upgrade to the latest version:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-php/php-cgi-4.3.11"
For more information, please see the referenced Gentoo Linux advisory.
RedHat Fedora has released advisory FEDORA-2005-315 for their Core 3 product. Please see the referenced advisory for more information.
Mandriva has released advisory MDKSA-2005:072 to address these issues. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat released advisory RHSA-2005:405-06 as well as fixes to address this and other issues on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisories for additional information.
SuSE has released advisory SUSE-SR:2005:012 and fixes for this issue. Fixes can be obtained through the SuSE FTP server or by using the YaST Online Update.
SGI has released an advisory 20050501-01-U including updated SGI ProPack 3
Service Pack 5 packages to address this BID and other issues. Please see
the referenced advisory for more information.
Apple has released security advisory APPLE-SA-2005-06-08 along with fixes dealing with this issue for Mac OS X 10.4.1 and Mac OS X 10.3.9. Please see the referenced advisory for more information.
RedHat Fedora has released Fedora Legacy security advisory FLSA:155505 addressing this issue. Please see the referenced advisory for further information.
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.3.9
Apple Mac OS X Server 10.4.1
Apple Mac OS X 10.4.1
PHP PHP 4.3
PHP PHP 4.3.1
PHP PHP 4.3.10
PHP PHP 4.3.2
PHP PHP 4.3.3
PHP PHP 4.3.4
PHP PHP 4.3.5
PHP PHP 4.3.6
PHP PHP 4.3.7
PHP PHP 4.3.8
PHP PHP 4.3.9
Solution:
Avaya has released an advisory (ASA-2005-136) that acknowledges this vulnerability for Avaya products. Please see the referenced Avaya advisory for further details.
Conectiva has released an advisory (CLSA-2005:955) and fixes to address this and other issues. Please see the referenced advisory for further information regarding obtaining and applying appropriate updates.
Turbolinux has released advisory TLSA-2005-50 along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
Peachtree Linux has released an advisory (PLSN-0001) including updated packages to address this issue. Please see the referenced advisory for more information.
Ubuntu has released advisory USN-112-1 to provide fixes for this issue. Please see the attached advisory for further information on obtaining and applying fixes.
This issue has been addressed in PHP 4.3.11.
Gentoo Linux has released advisory GLSA 200504-15 dealing with this issue. Gentoo advises that all users upgrade their packages by executing the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-php/php-4.3.11"
All mod_php users should upgrade to the latest version:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-php/mod_php-4.3.11"
All php-cgi users should upgrade to the latest version:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-php/php-cgi-4.3.11"
For more information, please see the referenced Gentoo Linux advisory.
RedHat Fedora has released advisory FEDORA-2005-315 for their Core 3 product. Please see the referenced advisory for more information.
Mandriva has released advisory MDKSA-2005:072 to address these issues. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat released advisory RHSA-2005:405-06 as well as fixes to address this and other issues on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisories for additional information.
SuSE has released advisory SUSE-SR:2005:012 and fixes for this issue. Fixes can be obtained through the SuSE FTP server or by using the YaST Online Update.
SGI has released an advisory 20050501-01-U including updated SGI ProPack 3
Service Pack 5 packages to address this BID and other issues. Please see
the referenced advisory for more information.
Apple has released security advisory APPLE-SA-2005-06-08 along with fixes dealing with this issue for Mac OS X 10.4.1 and Mac OS X 10.3.9. Please see the referenced advisory for more information.
RedHat Fedora has released Fedora Legacy security advisory FLSA:155505 addressing this issue. Please see the referenced advisory for further information.
Apple Mac OS X Server 10.3.9
-
Apple SecUpd2005-006Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=06439&plat form=osx&method=sa/SecUpd2005-006Pan.dmg
Apple Mac OS X 10.3.9
-
Apple SecUpd2005-006Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=06439&plat form=osx&method=sa/SecUpd2005-006Pan.dmg
Apple Mac OS X Server 10.4.1
-
Apple SecUpd2005-006Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=06440&plat form=osx&method=sa/SecUpd2005-006Ti.dmg
Apple Mac OS X 10.4.1
-
Apple SecUpd2005-006Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=06440&plat form=osx&method=sa/SecUpd2005-006Ti.dmg
PHP PHP 4.3
-
PHP Group PHP 4.3.11
http://ca.php.net/get/php-4.3.11.tar.gz/from/a/mirror
PHP PHP 4.3.1
-
PHP Group PHP 4.3.11
http://ca.php.net/get/php-4.3.11.tar.gz/from/a/mirror
PHP PHP 4.3.10
-
Mandriva lib64php_common432-4.3.10-7.1.102mdk.x86_64.rpm
Mandrake Linux 10.2/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libphp_common432-4.3.10-7.1.102mdk.i586.rpm
Mandrake Linux 10.2
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cgi-4.3.10-7.1.102mdk.i586.rpm
Mandrake Linux 10.2
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cgi-4.3.10-7.1.102mdk.x86_64.rpm
Mandrake Linux 10.2/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cli-4.3.10-7.1.102mdk.i586.rpm
Mandrake Linux 10.2
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cli-4.3.10-7.1.102mdk.x86_64.rpm
Mandrake Linux 10.2/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php432-devel-4.3.10-7.1.102mdk.i586.rpm
Mandrake Linux 10.2
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php432-devel-4.3.10-7.1.102mdk.x86_64.rpm
Mandrake Linux 10.2/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
PHP Group PHP 4.3.11
http://ca.php.net/get/php-4.3.11.tar.gz/from/a/mirror
PHP PHP 4.3.2
-
PHP Group PHP 4.3.11
http://ca.php.net/get/php-4.3.11.tar.gz/from/a/mirror
PHP PHP 4.3.3
-
PHP Group PHP 4.3.11
http://ca.php.net/get/php-4.3.11.tar.gz/from/a/mirror
PHP PHP 4.3.4
-
Mandriva lib64php_common432-4.3.4-4.5.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libphp_common432-4.3.4-4.5.100mdk.i586.rpm
Mandrake Linux 10.0
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libphp_common432-4.3.4-4.5.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libphp_common432-4.3.4-4.5.C30mdk.i586.rpm
Mandrake Corporate Server 3.0/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cgi-4.3.4-4.5.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cgi-4.3.4-4.5.100mdk.i586.rpm
Mandrake Linux 10.0
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cgi-4.3.4-4.5.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cgi-4.3.4-4.5.C30mdk.i586.rpm
Mandrake Corporate Server 3.0/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cli-4.3.4-4.5.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cli-4.3.4-4.5.100mdk.i586.rpm
Mandrake Linux 10.0
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cli-4.3.4-4.5.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cli-4.3.4-4.5.C30mdk.i586.rpm
Mandrake Corporate Server 3.0/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php432-devel-4.3.4-4.5.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php432-devel-4.3.4-4.5.100mdk.i586.rpm
Mandrake Linux 10.0
http://www1.mandrivalinux.com/en/ftp.php3 -
PHP Group PHP 4.3.11
http://ca.php.net/get/php-4.3.11.tar.gz/from/a/mirror
PHP PHP 4.3.5
-
PHP Group PHP 4.3.11
http://ca.php.net/get/php-4.3.11.tar.gz/from/a/mirror
PHP PHP 4.3.6
-
PHP Group PHP 4.3.11
http://ca.php.net/get/php-4.3.11.tar.gz/from/a/mirror
PHP PHP 4.3.7
-
PHP Group PHP 4.3.11
http://ca.php.net/get/php-4.3.11.tar.gz/from/a/mirror
PHP PHP 4.3.8
-
Mandriva lib64php_common432-4.3.8-3.3.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libphp_common432-4.3.8-3.3.101mdk.i586.rpm
Mandrake Linux 10.1
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cgi-4.3.8-3.3.101mdk.i586.rpm
Mandrake Linux 10.1
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cgi-4.3.8-3.3.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cli-4.3.8-3.3.101mdk.i586.rpm
Mandrake Linux 10.1
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-cli-4.3.8-3.3.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
PHP Group PHP 4.3.11
http://ca.php.net/get/php-4.3.11.tar.gz/from/a/mirror -
Ubuntu libapache2-mod-php4_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/p/php4/libapache2-mod-php4 _4.3.8-3ubuntu7.8_amd64.deb -
Ubuntu libapache2-mod-php4_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/p/php4/libapache2-mod-php4 _4.3.8-3ubuntu7.8_i386.deb -
Ubuntu libapache2-mod-php4_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/p/php4/libapache2-mod-php4 _4.3.8-3ubuntu7.8_powerpc.deb -
Ubuntu php4-cgi_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/p/php4/php4-cgi_4.3.8-3ubu ntu7.8_amd64.deb -
Ubuntu php4-cgi_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/p/php4/php4-cgi_4.3.8-3ubu ntu7.8_i386.deb -
Ubuntu php4-cgi_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/p/php4/php4-cgi_4.3.8-3ubu ntu7.8_powerpc.deb -
Ubuntu php4-curl_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-curl_4.3.8 -3ubuntu7.8_amd64.deb -
Ubuntu php4-curl_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-curl_4.3.8 -3ubuntu7.8_i386.deb -
Ubuntu php4-curl_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-curl_4.3.8 -3ubuntu7.8_powerpc.deb -
Ubuntu php4-dev_4.3.8-3ubuntu7.8_all.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/p/php4/php4-dev_4.3.8-3ubu ntu7.8_all.deb -
Ubuntu php4-domxml_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-domxml_4.3 .8-3ubuntu7.8_amd64.deb -
Ubuntu php4-domxml_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-domxml_4.3 .8-3ubuntu7.8_i386.deb -
Ubuntu php4-domxml_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-domxml_4.3 .8-3ubuntu7.8_powerpc.deb -
Ubuntu php4-gd_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-gd_4.3.8-3 ubuntu7.8_amd64.deb -
Ubuntu php4-gd_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-gd_4.3.8-3 ubuntu7.8_i386.deb -
Ubuntu php4-gd_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-gd_4.3.8-3 ubuntu7.8_powerpc.deb -
Ubuntu php4-ldap_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-ldap_4.3.8 -3ubuntu7.8_amd64.deb -
Ubuntu php4-ldap_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-ldap_4.3.8 -3ubuntu7.8_i386.deb -
Ubuntu php4-ldap_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-ldap_4.3.8 -3ubuntu7.8_powerpc.deb -
Ubuntu php4-mcal_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-mcal_4.3.8 -3ubuntu7.8_amd64.deb -
Ubuntu php4-mcal_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-mcal_4.3.8 -3ubuntu7.8_i386.deb -
Ubuntu php4-mcal_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-mcal_4.3.8 -3ubuntu7.8_powerpc.deb -
Ubuntu php4-mhash_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-mhash_4.3. 8-3ubuntu7.8_amd64.deb -
Ubuntu php4-mhash_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-mhash_4.3. 8-3ubuntu7.8_i386.deb -
Ubuntu php4-mhash_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-mhash_4.3. 8-3ubuntu7.8_powerpc.deb -
Ubuntu php4-mysql_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-mysql_4.3. 8-3ubuntu7.8_amd64.deb -
Ubuntu php4-mysql_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-mysql_4.3. 8-3ubuntu7.8_i386.deb -
Ubuntu php4-mysql_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-mysql_4.3. 8-3ubuntu7.8_powerpc.deb -
Ubuntu php4-odbc_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-odbc_4.3.8 -3ubuntu7.8_amd64.deb -
Ubuntu php4-odbc_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-odbc_4.3.8 -3ubuntu7.8_i386.deb -
Ubuntu php4-odbc_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-odbc_4.3.8 -3ubuntu7.8_powerpc.deb -
Ubuntu php4-pear_4.3.8-3ubuntu7.8_all.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-pear_4.3.8 -3ubuntu7.8_all.deb -
Ubuntu php4-recode_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-recode_4.3 .8-3ubuntu7.8_amd64.deb -
Ubuntu php4-recode_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-recode_4.3 .8-3ubuntu7.8_i386.deb -
Ubuntu php4-recode_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-recode_4.3 .8-3ubuntu7.8_powerpc.deb -
Ubuntu php4-snmp_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-snmp_4.3.8 -3ubuntu7.8_amd64.deb -
Ubuntu php4-snmp_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-snmp_4.3.8 -3ubuntu7.8_i386.deb -
Ubuntu php4-snmp_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-snmp_4.3.8 -3ubuntu7.8_powerpc.deb -
Ubuntu php4-sybase_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-sybase_4.3 .8-3ubuntu7.8_amd64.deb -
Ubuntu php4-sybase_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-sybase_4.3 .8-3ubuntu7.8_i386.deb -
Ubuntu php4-sybase_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-sybase_4.3 .8-3ubuntu7.8_powerpc.deb -
Ubuntu php4-xslt_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-xslt_4.3.8 -3ubuntu7.8_amd64.deb -
Ubuntu php4-xslt_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-xslt_4.3.8 -3ubuntu7.8_i386.deb -
Ubuntu php4-xslt_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4-xslt_4.3.8 -3ubuntu7.8_powerpc.deb -
Ubuntu php4_4.3.8-3ubuntu7.8_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4_4.3.8-3ubu ntu7.8_amd64.deb -
Ubuntu php4_4.3.8-3ubuntu7.8_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4_4.3.8-3ubu ntu7.8_i386.deb -
Ubuntu php4_4.3.8-3ubuntu7.8_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/p/php4/php4_4.3.8-3ubu ntu7.8_powerpc.deb
PHP PHP 4.3.9
-
Fedora php-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-debuginfo-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-debuginfo-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-devel-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-devel-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-domxml-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-domxml-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-gd-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-gd-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-imap-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-imap-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-ldap-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-ldap-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-mbstring-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-mbstring-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-mysql-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-mysql-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-ncurses-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-ncurses-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-odbc-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-odbc-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-pear-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-pear-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-pgsql-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-pgsql-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-snmp-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-snmp-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-xmlrpc-4.3.11-2.4.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora php-xmlrpc-4.3.11-2.4.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
PHP Group PHP 4.3.11
http://ca.php.net/get/php-4.3.11.tar.gz/from/a/mirror
References
PHP Group Exif Module IFD Tag Integer Overflow Vulnerability
References:
References:
- ASA-2005-136 - PHP (Avaya)
- CLSA-2005:955 : Fixes for multiple php4 vulnerabilities (Conectiva)
- PHP 4 ChangeLog - Version 4.3.11 (PHP Group)
- PHP Homepage (PHP Group)
- RHSA-2005:405-06 - PHP security update (RedHat)
- [PLSN-0001] - Multiple PHP vulnerabilities (Peachtree Linux Security Team
)