PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability
BID:50907
Info
PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability
| Bugtraq ID: | 50907 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-4566 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2011 12:00AM |
| Updated: | Mar 19 2015 08:17AM |
| Credit: | flolechaud at gmail dot com |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Turbolinux Client 2008 Turbolinux Appliance Server 3.0 x64 Turbolinux Appliance Server 3.0 Turbolinux 11 Server x64 Turbolinux 11 Server 0 SuSE SUSE Linux Enterprise Server for VMware 11 SP1 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise SDK 11 SP1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server PHP PHP 5.3.8 PHP PHP 5.3.7 PHP PHP 5.3.6 PHP PHP 5.3.5 PHP PHP 5.3.2 PHP PHP 5.3.1 PHP PHP 5.3 PHP PHP 5.2.17 PHP PHP 5.2.15 PHP PHP 5.2.13 PHP PHP 5.2.12 PHP PHP 5.2.11 PHP PHP 5.2.10 PHP PHP 5.2.9 -2 PHP PHP 5.2.9 PHP PHP 5.2.8 PHP PHP 5.2.7 PHP PHP 5.2.6 PHP PHP 5.2.5 PHP PHP 5.2.4 PHP PHP 5.2.3 PHP PHP 5.2.2 PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 5.4.0beta2 PHP PHP 5.3.5 PHP PHP 5.3.4 RC1 PHP PHP 5.3.4 PHP PHP 5.3.3 PHP PHP 5.2.14 PHP PHP 5.2 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Oracle Enterprise Linux 4 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Juniper CTPView 4.6 Juniper CTPView 4.5 Juniper CTPView 4.4 Juniper CTPView 4.3 Juniper CTPView 4.2 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya IP Office Application Server 8.0 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Communication Manager 4.0 Avaya Aura Communication Manager 4.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Apple Mac OS X Server 10.7.3 Apple Mac OS X Server 10.7.2 Apple Mac OS X Server 10.7.1 Apple Mac OS X Server 10.7 Apple Mac OS X 10.7.3 Apple Mac OS X 10.7.2 Apple Mac OS X 10.7.1 Apple Mac OS X 10.7 |
| Not Vulnerable: |
PHP PHP 5.3.9 Juniper CTPView 7.0R1 Avaya Aura Communication Manager 6.3 Apple Mac OS X Server 10.7.4 Apple Mac OS X 10.7.4 |
Discussion
PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability
PHP is prone to an integer-overflow vulnerability because it fails to ensure that integer values are not overrun.
Successful exploits of this vulnerability allow remote attackers to execute arbitrary code in the context of a webserver affected by the issue. Failed attempts will likely result in denial-of-service conditions.
PHP 5.4.0beta2 is vulnerable; other versions may also be affected.
PHP is prone to an integer-overflow vulnerability because it fails to ensure that integer values are not overrun.
Successful exploits of this vulnerability allow remote attackers to execute arbitrary code in the context of a webserver affected by the issue. Failed attempts will likely result in denial-of-service conditions.
PHP 5.4.0beta2 is vulnerable; other versions may also be affected.
Exploit / POC
PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability
The following proof-of-concept code is available:
The following proof-of-concept code is available:
Solution / Fix
PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.7.2
Apple Mac OS X Server 10.7.2
Apple Mac OS X 10.7.3
MandrakeSoft Enterprise Server 5
Apple Mac OS X 10.7.1
Mandriva Linux Mandrake 2011
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.7.2
-
Apple MacOSXUpdCombo10.7.4.dmg
For OS X Lion v10.7 and v10.7.2
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.7.2
-
Apple MacOSXServerUpdCombo10.7.4.dmg
For OS X Lion Server v10.7 and v10.7.2
http://www.apple.com/support/downloads/
Apple Mac OS X 10.7.3
-
Apple MacOSXUpd10.7.4.dmg
For OS X Lion v10.7.3
http://www.apple.com/support/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva apache-mod_php-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libmbfl-devel-1.1.0-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libmbfl1-1.1.0-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libming-devel-0.4.4-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libming1-0.4.4-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libmonetra-devel-7.0.4-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libmonetra7-7.0.4-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libphp5_common5-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libsphinxclient-devel-0.9.9-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libsphinxclient0-0.9.9-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libstemmer-devel-0-5.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libstemmer0-0-5.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxmlrpc-epi-devel-0.54-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxmlrpc-epi0-0.54-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libyaz-devel-3.0.48-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libyaz3-3.0.48-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva ming-utils-0.4.4-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva perl-SWF-0.4.4-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-apc-3.1.10-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-apc-admin-3.1.10-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-bcmath-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-bz2-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-calendar-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-cgi-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-cli-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ctype-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-curl-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-dba-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-dbx-1.1.0-30.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-devel-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-dio-0.0.5-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-doc-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-dom-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-eaccelerator-0.9.6.1-0.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-eaccelerator-admin-0.9.6.1-0.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-enchant-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-exif-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-fam-5.0.1-3.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-fileinfo-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-filepro-5.1.6-13.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-filter-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-fpm-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ftp-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gd-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gettext-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gmp-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gtk2-2.0.1-2.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-hash-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-iconv-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-imagick-3.0.1-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-imap-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ini-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-intl-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-json-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ldap-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mailparse-2.1.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mbstring-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mcal-0.6-23.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mcrypt-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mcve-7.0.3-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mdbtools-1.0.0-4.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-memcache-3.0.6-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ming-5.2.10-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mssql-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mysql-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mysqli-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mysqlnd-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-odbc-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-openssl-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-optimizer-0.1-0.alpha2.0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pcntl-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_dblib-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_mysql-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_odbc-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_pgsql-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_sqlite-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-perl-1.0.0-32.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pgsql-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-phar-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-posix-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pspell-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-radius-1.2.5-7.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-readline-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-recode-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sasl-0.1.0-21.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-session-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-shmop-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-snmp-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-soap-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sockets-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sphinx-1.2.0-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sqlite-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sqlite3-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ssh2-0.11.3-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-suhosin-0.9.33-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sybase_ct-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvmsg-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvsem-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvshm-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-tclink-3.4.5-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-tidy-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-timezonedb-2012.3-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-tokenizer-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-translit-0.6.1-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-vld-0.11.1-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-wddx-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xattr-1.1.0-2.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xcache-1.3.2-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xcache-admin-1.3.2-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xdebug-2.1.4-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xml-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlreader-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlrpc-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlwriter-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xsl-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-yaz-1.1.1-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-zip-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-zlib-5.3.13-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva python-SWF-0.4.4-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva sphinx-0.9.9-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva stemwords-0-5.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva yaz-3.0.48-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Apple Mac OS X 10.7.1
-
Apple MacOSXUpdCombo10.7.4.dmg
For OS X Lion v10.7 and v10.7.2
http://www.apple.com/support/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva libphp5_common5-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-bcmath-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-bz2-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-calendar-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-cgi-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-cli-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ctype-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-curl-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-dba-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-devel-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-doc-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-dom-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-enchant-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-exif-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-fileinfo-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-filter-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-fpm-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ftp-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gd-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gettext-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gmp-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-hash-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-iconv-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-imap-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ini-5.3.8-1.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-intl-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-json-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ldap-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mbstring-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mcrypt-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mssql-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mysql-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mysqli-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-odbc-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-openssl-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pcntl-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_dblib-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_mysql-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_odbc-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_pgsql-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_sqlite-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pgsql-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-phar-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-posix-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pspell-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-readline-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-recode-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-session-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-shmop-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-snmp-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-soap-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sockets-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sqlite-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sqlite3-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sybase_ct-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvmsg-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvsem-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvshm-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-tidy-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-tokenizer-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-wddx-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xml-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlreader-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlrpc-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlwriter-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xsl-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-zip-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-zlib-5.3.8-1.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
References
PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability
References:
References:
- PHP 5.3.9 Released! (PHP)
- PHP Homepage (PHP)
- 2014-11 Security Bulletin: CTPView: Multiple Security vulnerabilities resolved b (Juniper)
- ASA-2012-068 php security update (RHSA-2012-0071) (Avaya)
- ASA-2012-119:php security update (RHSA-2012-0033) (Avaya)
- php53 and php security update (RHSA-2012-0019) (Avaya)
- Sec Bug #60150 Integer overflow during the parsing of invalid exif header (flolechaud at gmail dot com)
- Turbolinux Security Advisory TLSA-2012-14 (Turbolinux)