PHP 'ext/soap/php_xml.c' Multiple Arbitrary File Disclosure Vulnerabilities
BID:58766
Info
PHP 'ext/soap/php_xml.c' Multiple Arbitrary File Disclosure Vulnerabilities
| Bugtraq ID: | 58766 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-1643 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2013 12:00AM |
| Updated: | Apr 13 2015 09:19PM |
| Credit: | Vendor reported these issues. |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server for VMware 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise SDK 10 SP4 Slackware Linux x86_64 -current Slackware Linux 14.0 x86_64 Slackware Linux 14.0 Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux -current S.u.S.E. openSUSE 12.3 S.u.S.E. openSUSE 12.2 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux 5 Server PHP PHP 5.4.1 PHP PHP 5.3.21 PHP PHP 5.3.17 PHP PHP 5.3.16 PHP PHP 5.3.14 PHP PHP 5.3.13 PHP PHP 5.3.12 PHP PHP 5.3.1 PHP PHP 5.3 PHP PHP 5.4.11 PHP PHP 5.3.15 PHP PHP 5.3.11 PHP PHP 5.3.10 Oracle Solaris 11.1 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 Avaya Voice Portal 5.1.3 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP3 Avaya Voice Portal 5.1 SP2 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya IP Office Server Edition 9.0 Avaya IP Office Server Edition 8.1 Avaya IP Office Application Server 9.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Messaging 6.1.1 Avaya Aura Messaging 6.2 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0.2 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 6.0 SP2 Avaya Aura Experience Portal 6.0 SP1 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 7.0 Avaya Aura Communication Manager Utility Services 6.3 Avaya Aura Communication Manager Utility Services 6.2.5.0.15 Avaya Aura Communication Manager Utility Services 6.2.4.0.15 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 SP 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.3 Avaya Aura Communication Manager 6.2 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.4 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Apple Mac OS X Server 10.7.5 Apple Mac OS X Server 10.6.8 Apple Mac OS X 10.8.4 Apple Mac OS X 10.8.2 Apple Mac OS X 10.8.1 Apple Mac OS X 10.7.5 Apple Mac OS X 10.8.3 Apple Mac OS X 10.8 Apple Mac OS X 10.6.8 |
| Not Vulnerable: |
PHP PHP 5.3.22 PHP PHP 5.4.12 Oracle Solaris 11.1.17.5.0 Apple Mac OS X 10.8.5 |
Discussion
PHP 'ext/soap/php_xml.c' Multiple Arbitrary File Disclosure Vulnerabilities
PHP is prone to multiple arbitrary file-disclosure vulnerabilities because the application fails to sanitize user-supplied input.
An authenticated attacker can exploit these vulnerabilities to view arbitrary files within the context of the affected application. Other attacks are also possible.
Note: These issues were previously covered in BID 58224 (PHP Arbitrary File Disclosure and Arbitrary File Write Vulnerabilities), but have been separated into their own record to better document them.
Versions prior to PHP 5.3.22 and 5.4.12 are vulnerable.
PHP is prone to multiple arbitrary file-disclosure vulnerabilities because the application fails to sanitize user-supplied input.
An authenticated attacker can exploit these vulnerabilities to view arbitrary files within the context of the affected application. Other attacks are also possible.
Note: These issues were previously covered in BID 58224 (PHP Arbitrary File Disclosure and Arbitrary File Write Vulnerabilities), but have been separated into their own record to better document them.
Versions prior to PHP 5.3.22 and 5.4.12 are vulnerable.
Exploit / POC
PHP 'ext/soap/php_xml.c' Multiple Arbitrary File Disclosure Vulnerabilities
Attackers can exploit these issues through a browser.
Attackers can exploit these issues through a browser.
Solution / Fix
PHP 'ext/soap/php_xml.c' Multiple Arbitrary File Disclosure Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Slackware Linux 12.2
Slackware Linux 13.1
Apple Mac OS X 10.6.8
Slackware Linux x86_64 -current
Slackware Linux 14.0 x86_64
MandrakeSoft Enterprise Server 5
Slackware Linux 13.0 x86_64
Mandriva Linux Mandrake 2011
Slackware Linux 13.37
Apple Mac OS X 10.8
Apple Mac OS X Server 10.6.8
Slackware Linux -current
Apple Mac OS X Server 10.7.5
Apple Mac OS X 10.8.4
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Slackware Linux 12.2
-
Slackware php-5.3.23-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ php-5.3.23-i486-1_slack12.2.tgz
Slackware Linux 13.1
-
Slackware php-5.3.23-i486-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ php-5.3.23-i486-1_slack13.1.txz
Apple Mac OS X 10.6.8
-
Apple For Mac OS X 10.6.8 SecUpd2013-004.dmg
http://www.apple.com/support/downloads/ -
Apple For Mac OS X Server 10.6.8 SecUpdSrvr2013-004.dmg
http://support.apple.com/downloads/
Slackware Linux x86_64 -current
-
Slackware php-5.4.13-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ n/php-5.4.13-x86_64-1.txz
Slackware Linux 14.0 x86_64
-
Slackware php-5.4.13-x86_64-1_slack14.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/package s/php-5.4.13-x86_64-1_slack14.0.txz
MandrakeSoft Enterprise Server 5
-
Mandriva apache-mod_php-5.3.22-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libphp5_common5-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-apc-3.1.13-0.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-apc-admin-3.1.13-0.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-bcmath-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-bz2-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-calendar-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-cgi-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-cli-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ctype-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-curl-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-dba-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-devel-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-doc-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-dom-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-eaccelerator-0.9.6.1-0.9mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-eaccelerator-admin-0.9.6.1-0.9mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-enchant-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-exif-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-fileinfo-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-filter-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-fpm-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ftp-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gd-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gd-bundled-5.3.22-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gettext-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gmp-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-hash-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-iconv-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-imap-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ini-5.3.22-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-intl-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-json-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ldap-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mbstring-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mcrypt-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mssql-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mysql-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mysqli-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mysqlnd-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-odbc-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-openssl-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pcntl-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_dblib-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_mysql-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_odbc-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_pgsql-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_sqlite-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pgsql-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-phar-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-posix-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pspell-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-readline-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-recode-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-session-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-shmop-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-snmp-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-soap-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sockets-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sqlite-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sqlite3-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sybase_ct-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvmsg-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvsem-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvshm-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-tidy-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-tokenizer-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-wddx-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xml-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlreader-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlrpc-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlwriter-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xsl-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-zip-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-zlib-5.3.22-0.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Slackware Linux 13.0 x86_64
-
Slackware php-5.3.23-x86_64-1_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/package s/php-5.3.23-x86_64-1_slack13.0.txz
Mandriva Linux Mandrake 2011
-
Mandriva apache-mod_php-5.3.22-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libphp5_common5-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-apc-3.1.13-0.3-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-apc-admin-3.1.13-0.3-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-bcmath-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-bz2-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-calendar-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-cgi-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-cli-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ctype-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-curl-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-dba-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-devel-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-doc-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-dom-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-eaccelerator-0.9.6.1-9.3-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-eaccelerator-admin-0.9.6.1-9.3-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-enchant-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-exif-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-fileinfo-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-filter-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-fpm-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ftp-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gd-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gettext-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-gmp-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-hash-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-iconv-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-imap-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ini-5.3.22-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-intl-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-json-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-ldap-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mbstring-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mcrypt-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mssql-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mysql-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mysqli-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mysqlnd-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-odbc-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-openssl-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pcntl-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_dblib-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_mysql-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_odbc-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_pgsql-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pdo_sqlite-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pgsql-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-phar-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-posix-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-pspell-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-readline-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-recode-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-session-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-shmop-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-snmp-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-soap-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sockets-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sqlite-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sqlite3-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sybase_ct-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvmsg-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvsem-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-sysvshm-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-tidy-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-tokenizer-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-wddx-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xml-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlreader-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlrpc-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xmlwriter-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-xsl-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-zip-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-zlib-5.3.22-0.2-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
Slackware Linux 13.37
-
Slackware php-5.3.23-i486-1_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages /php-5.3.23-i486-1_slack13.37.txz
Apple Mac OS X 10.8
-
Apple OSXUpdCombo10.8.5.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.8
-
Apple For Mac OS X Server 10.6.8 SecUpdSrvr2013-004.dmg
http://support.apple.com/downloads/
Slackware Linux -current
-
Slackware php-5.4.13-i486-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/ph p-5.4.13-i486-1.txz
Apple Mac OS X Server 10.7.5
-
Apple For OS X Lion Server 10.7.5 SecUpdSrvr2013-004.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X 10.8.4
-
Apple OSXUpd10.8.5.dmg
http://www.apple.com/support/downloads/
References
PHP 'ext/soap/php_xml.c' Multiple Arbitrary File Disclosure Vulnerabilities
References:
References:
- add CVEs (Stanislav Malyshev)
- Disabled external entities loading (Dmitry Stogov)
- Disabled external entities loading Commit (Dmitry Stogov)
- Multiple vulnerabilities in PHP (Oracle)
- PHP 5.3.22 Product Page (PHP)
- PHP Homepage (PHP)
- php security, bug fix, and enhancement update (RHSA-2013-1615) (Avaya)
- Proper bit reset code (Dmitry Stogov)
- Proper bit reset code Commit (Dmitry Stogov)
- About the security content of OS X Mountain Lion v10.8.5 and Security Update 201 (Apple)
- php security update (RHSA-2013-1814) (Avaya)