LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
What is the most important Linux security technology?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Securitydistro
Latest Newsletters
Linux Advisory Watch: December 19th, 2014
Linux Advisory Watch: December 12th, 2014
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Red Hat: 'php' updates Print E-mail
User Rating:      How can I rate this item?
Posted by LinuxSecurity.com Team   
RedHat Linux This update fixes several general problems with php3 and 4, along with some security holes in versions 4.0 through 4.0.4 of php.

---------------------------------------------------------------------
                   Red Hat, Inc. Red Hat Security Advisory

Synopsis:          Updated PHP packages available for Red Hat Linux 5.2, 6.x,
and 7
Advisory ID:       RHSA-2000:136-10
Issue date:        2000-12-20
Updated on:        2001-01-24
Product:           Red Hat Linux
Keywords:          php multipart gd engine
Cross references:  RHSA-2000:88 RHBA-2000:112
Obsoletes:         
---------------------------------------------------------------------

1. Topic:

Updated PHP packages are now available for Red Hat Linux 5.2, 6.x, and 7.

2. Relevant releases/architectures:

Red Hat Linux 5.2 - alpha, i386, sparc

Red Hat Linux 6.0 - i386, sparc

Red Hat Linux 6.1 - alpha, i386, sparc

Red Hat Linux 6.2 - alpha, i386, sparc

Red Hat Linux 7.0 - alpha, i386

3. Problem description:

Clients uploading "multipart/form-data" information with form requests
could cause PHP 3.0.17 to crash.  The GD module was not compiled into the
previously-issued PHP 4.0.3pl1 errata packages.  The php-mysql package is
linked against an older version of the libmysqlclient shared library, which
was obsoleted by a previous MySQL errata.  Security holes in versions 4.0.0
through 4.0.4 of the PHP Apache module have been found.

4. Solution:

Because of dependencies, the packages must be installed as a group.

After downloading all RPMs needed for your particular architecture, run:

rpm -Fvh php*

Then restart your web server:

/etc/rc.d/init.d/httpd restart

5. Bug IDs fixed  (http://bugzilla.Red Hat.com/bugzilla for more info):

19906 - PHP 3.0.17-1.6.2 crashes apache reproducable
21291 - php should be rebuild on new environment
21620 - configure option --enable-wddx not used
21664 - updated Red Hat 7 PHP rpm's broken
22376 - php-4.0.3pl1 from 7.0 errata fails to install gd.so ld
23690 - php-mysql needs rebuild in light of mysql-3.23.29-1
23902 - PHP4.0.4pl1 solve 2 security problems

6. RPMs required:

Red Hat Linux 5.2:

SRPMS: 
ftp://updates.Red Hat.com/5.2/SRPMS/php-3.0.18-1.5.x.src.rpm

alpha: 
ftp://updates.Red Hat.com/5.2/alpha/php-3.0.18-1.5.x.alpha.rpm 
ftp://updates.Red Hat.com/5.2/alpha/php-manual-3.0.18-1.5.x.alpha.rpm 
ftp://updates.Red Hat.com/5.2/alpha/php-pgsql-3.0.18-1.5.x.alpha.rpm

i386: 
ftp://updates.Red Hat.com/5.2/i386/php-3.0.18-1.5.x.i386.rpm 
ftp://updates.Red Hat.com/5.2/i386/php-manual-3.0.18-1.5.x.i386.rpm 
ftp://updates.Red Hat.com/5.2/i386/php-pgsql-3.0.18-1.5.x.i386.rpm

sparc: 
ftp://updates.Red Hat.com/5.2/sparc/php-3.0.18-1.5.x.sparc.rpm 
ftp://updates.Red Hat.com/5.2/sparc/php-manual-3.0.18-1.5.x.sparc.rpm 
ftp://updates.Red Hat.com/5.2/sparc/php-pgsql-3.0.18-1.5.x.sparc.rpm

Red Hat Linux 6.0:

SRPMS: 
ftp://updates.Red Hat.com/6.0/SRPMS/php-3.0.18-1.6.x.src.rpm

i386: 
ftp://updates.Red Hat.com/6.0/i386/php-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.0/i386/php-imap-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.0/i386/php-ldap-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.0/i386/php-manual-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.0/i386/php-pgsql-3.0.18-1.6.x.i386.rpm

sparc: 
ftp://updates.Red Hat.com/6.0/sparc/php-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.0/sparc/php-imap-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.0/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.0/sparc/php-manual-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.0/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm

Red Hat Linux 6.1:

SRPMS: 
ftp://updates.Red Hat.com/6.1/SRPMS/php-3.0.18-1.6.x.src.rpm

alpha: 
ftp://updates.Red Hat.com/6.1/alpha/php-3.0.18-1.6.x.alpha.rpm 
ftp://updates.Red Hat.com/6.1/alpha/php-imap-3.0.18-1.6.x.alpha.rpm 
ftp://updates.Red Hat.com/6.1/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm 
ftp://updates.Red Hat.com/6.1/alpha/php-manual-3.0.18-1.6.x.alpha.rpm 
ftp://updates.Red Hat.com/6.1/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm

i386: 
ftp://updates.Red Hat.com/6.1/i386/php-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.1/i386/php-imap-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.1/i386/php-ldap-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.1/i386/php-manual-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.1/i386/php-pgsql-3.0.18-1.6.x.i386.rpm

sparc: 
ftp://updates.Red Hat.com/6.1/sparc/php-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.1/sparc/php-imap-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.1/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.1/sparc/php-manual-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.1/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm

Red Hat Linux 6.2:

SRPMS: 
ftp://updates.Red Hat.com/6.2/SRPMS/php-3.0.18-1.6.x.src.rpm

alpha: 
ftp://updates.Red Hat.com/6.2/alpha/php-3.0.18-1.6.x.alpha.rpm 
ftp://updates.Red Hat.com/6.2/alpha/php-imap-3.0.18-1.6.x.alpha.rpm 
ftp://updates.Red Hat.com/6.2/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm 
ftp://updates.Red Hat.com/6.2/alpha/php-manual-3.0.18-1.6.x.alpha.rpm 
ftp://updates.Red Hat.com/6.2/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm

i386: 
ftp://updates.Red Hat.com/6.2/i386/php-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.2/i386/php-imap-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.2/i386/php-ldap-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.2/i386/php-manual-3.0.18-1.6.x.i386.rpm 
ftp://updates.Red Hat.com/6.2/i386/php-pgsql-3.0.18-1.6.x.i386.rpm

sparc: 
ftp://updates.Red Hat.com/6.2/sparc/php-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.2/sparc/php-imap-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.2/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.2/sparc/php-manual-3.0.18-1.6.x.sparc.rpm 
ftp://updates.Red Hat.com/6.2/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm

Red Hat Linux 7.0:

SRPMS: 
ftp://updates.Red Hat.com/7.0/SRPMS/php-4.0.4pl1-3.src.rpm

alpha: 
ftp://updates.Red Hat.com/7.0/alpha/php-4.0.4pl1-3.alpha.rpm 
ftp://updates.Red Hat.com/7.0/alpha/php-imap-4.0.4pl1-3.alpha.rpm 
ftp://updates.Red Hat.com/7.0/alpha/php-ldap-4.0.4pl1-3.alpha.rpm 
ftp://updates.Red Hat.com/7.0/alpha/php-manual-4.0.4pl1-3.alpha.rpm 
ftp://updates.Red Hat.com/7.0/alpha/php-mysql-4.0.4pl1-3.alpha.rpm 
ftp://updates.Red Hat.com/7.0/alpha/php-pgsql-4.0.4pl1-3.alpha.rpm

i386: 
ftp://updates.Red Hat.com/7.0/i386/php-4.0.4pl1-3.i386.rpm 
ftp://updates.Red Hat.com/7.0/i386/php-imap-4.0.4pl1-3.i386.rpm 
ftp://updates.Red Hat.com/7.0/i386/php-ldap-4.0.4pl1-3.i386.rpm 
ftp://updates.Red Hat.com/7.0/i386/php-manual-4.0.4pl1-3.i386.rpm 
ftp://updates.Red Hat.com/7.0/i386/php-mysql-4.0.4pl1-3.i386.rpm 
ftp://updates.Red Hat.com/7.0/i386/php-pgsql-4.0.4pl1-3.i386.rpm



7. Verification:

MD5 sum                           Package Name
--------------------------------------------------------------------------
fd62a3d0460fb6442d01f661e95275ab  5.2/SRPMS/php-3.0.18-1.5.x.src.rpm
625d416b98954143c0736dfd2143831b  5.2/alpha/php-3.0.18-1.5.x.alpha.rpm
5434b59b75a0227068b15175dbae3e1c  5.2/alpha/php-manual-3.0.18-1.5.x.alpha.rpm
6ee3385d9e4e7e0308e14d437bf197a9  5.2/alpha/php-pgsql-3.0.18-1.5.x.alpha.rpm
c9c2f6e2202519c204886cb01bbc5170  5.2/i386/php-3.0.18-1.5.x.i386.rpm
e2047b5a28cc6ec9c987a7c168d57bab  5.2/i386/php-manual-3.0.18-1.5.x.i386.rpm
3880561630fbb66dcc8432601010904d  5.2/i386/php-pgsql-3.0.18-1.5.x.i386.rpm
913fcfeec79c5c9ee57d76c519f8e652  5.2/sparc/php-3.0.18-1.5.x.sparc.rpm
27f4790a441e0661322a54082e067699  5.2/sparc/php-manual-3.0.18-1.5.x.sparc.rpm
a81d8e856451349c7b9b9b0597aa97ad  5.2/sparc/php-pgsql-3.0.18-1.5.x.sparc.rpm
f135fa49dee86cb2fd9aba665cda64d1  6.0/SRPMS/php-3.0.18-1.6.x.src.rpm
13998f321e1787af7bac4f01e9e01b81  6.0/i386/php-3.0.18-1.6.x.i386.rpm
d7a6f3e9d64c1edbeb10a1170e0d90b2  6.0/i386/php-imap-3.0.18-1.6.x.i386.rpm
bd3d6c413faf3ca0e271c7195fe5c2b1  6.0/i386/php-ldap-3.0.18-1.6.x.i386.rpm
9e19cc6e58fbeff7095abcd02120174f  6.0/i386/php-manual-3.0.18-1.6.x.i386.rpm
adf510253a012e01d0cc1bb631fd423f  6.0/i386/php-pgsql-3.0.18-1.6.x.i386.rpm
9f54bf780fbef67a03d7065a6d69f762  6.0/sparc/php-3.0.18-1.6.x.sparc.rpm
d17460149d0375a991773bf6f296957a  6.0/sparc/php-imap-3.0.18-1.6.x.sparc.rpm
d4c00495db0fbb0014697afc25cc3eca  6.0/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm
9ffb47a272984fd2757e09747e859695  6.0/sparc/php-manual-3.0.18-1.6.x.sparc.rpm
09acd6bbd4c19a57c0bbf64fcd64f2b8  6.0/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm
f135fa49dee86cb2fd9aba665cda64d1  6.1/SRPMS/php-3.0.18-1.6.x.src.rpm
ce0b8c6d8be5db195b70c3631e75e200  6.1/alpha/php-3.0.18-1.6.x.alpha.rpm
42e64510ed0fcce493cc20181eafd419  6.1/alpha/php-imap-3.0.18-1.6.x.alpha.rpm
53ac23e30083ae09d3a0aee04039e666  6.1/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm
39491a3833a9bd926b81fdc500e9a39f  6.1/alpha/php-manual-3.0.18-1.6.x.alpha.rpm
85aeccf83a08e9d69c5464c17fc9c445  6.1/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm
13998f321e1787af7bac4f01e9e01b81  6.1/i386/php-3.0.18-1.6.x.i386.rpm
d7a6f3e9d64c1edbeb10a1170e0d90b2  6.1/i386/php-imap-3.0.18-1.6.x.i386.rpm
bd3d6c413faf3ca0e271c7195fe5c2b1  6.1/i386/php-ldap-3.0.18-1.6.x.i386.rpm
9e19cc6e58fbeff7095abcd02120174f  6.1/i386/php-manual-3.0.18-1.6.x.i386.rpm
adf510253a012e01d0cc1bb631fd423f  6.1/i386/php-pgsql-3.0.18-1.6.x.i386.rpm
9f54bf780fbef67a03d7065a6d69f762  6.1/sparc/php-3.0.18-1.6.x.sparc.rpm
d17460149d0375a991773bf6f296957a  6.1/sparc/php-imap-3.0.18-1.6.x.sparc.rpm
d4c00495db0fbb0014697afc25cc3eca  6.1/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm
9ffb47a272984fd2757e09747e859695  6.1/sparc/php-manual-3.0.18-1.6.x.sparc.rpm
09acd6bbd4c19a57c0bbf64fcd64f2b8  6.1/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm
f135fa49dee86cb2fd9aba665cda64d1  6.2/SRPMS/php-3.0.18-1.6.x.src.rpm
ce0b8c6d8be5db195b70c3631e75e200  6.2/alpha/php-3.0.18-1.6.x.alpha.rpm
42e64510ed0fcce493cc20181eafd419  6.2/alpha/php-imap-3.0.18-1.6.x.alpha.rpm
53ac23e30083ae09d3a0aee04039e666  6.2/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm
39491a3833a9bd926b81fdc500e9a39f  6.2/alpha/php-manual-3.0.18-1.6.x.alpha.rpm
85aeccf83a08e9d69c5464c17fc9c445  6.2/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm
13998f321e1787af7bac4f01e9e01b81  6.2/i386/php-3.0.18-1.6.x.i386.rpm
d7a6f3e9d64c1edbeb10a1170e0d90b2  6.2/i386/php-imap-3.0.18-1.6.x.i386.rpm
bd3d6c413faf3ca0e271c7195fe5c2b1  6.2/i386/php-ldap-3.0.18-1.6.x.i386.rpm
9e19cc6e58fbeff7095abcd02120174f  6.2/i386/php-manual-3.0.18-1.6.x.i386.rpm
adf510253a012e01d0cc1bb631fd423f  6.2/i386/php-pgsql-3.0.18-1.6.x.i386.rpm
9f54bf780fbef67a03d7065a6d69f762  6.2/sparc/php-3.0.18-1.6.x.sparc.rpm
d17460149d0375a991773bf6f296957a  6.2/sparc/php-imap-3.0.18-1.6.x.sparc.rpm
d4c00495db0fbb0014697afc25cc3eca  6.2/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm
9ffb47a272984fd2757e09747e859695  6.2/sparc/php-manual-3.0.18-1.6.x.sparc.rpm
09acd6bbd4c19a57c0bbf64fcd64f2b8  6.2/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm
fc2f89fb24cdcae8485a334f2e0f2372  7.0/SRPMS/php-4.0.4pl1-3.src.rpm
4f7b7d6c57c3d58595b394a6b69b0830  7.0/alpha/php-4.0.4pl1-3.alpha.rpm
bc11c5346d930ac12236856b8c64f33c  7.0/alpha/php-imap-4.0.4pl1-3.alpha.rpm
8d98cdcf391c251d96685d5dce7fe588  7.0/alpha/php-ldap-4.0.4pl1-3.alpha.rpm
92ad775f67ff1d74fae764aa592e1103  7.0/alpha/php-manual-4.0.4pl1-3.alpha.rpm
26b438a4f276cbdec1a22591214f4ad6  7.0/alpha/php-mysql-4.0.4pl1-3.alpha.rpm
ef1cd2ed0bf74a2dd491fe34c686f8b5  7.0/alpha/php-pgsql-4.0.4pl1-3.alpha.rpm
2946e063efcb2be68f789624168b1a8b  7.0/i386/php-4.0.4pl1-3.i386.rpm
fdb049b4572bff635b5327cdbfae1266  7.0/i386/php-imap-4.0.4pl1-3.i386.rpm
4408734b5dd1c60d325d95216999f938  7.0/i386/php-ldap-4.0.4pl1-3.i386.rpm
502a66f4e11d98cd3f266bd1f897f9d7  7.0/i386/php-manual-4.0.4pl1-3.i386.rpm
066bcf976c3f930d16f191813473218c  7.0/i386/php-mysql-4.0.4pl1-3.i386.rpm
1660362c37dd4b603aa733f2d92c2e94  7.0/i386/php-pgsql-4.0.4pl1-3.i386.rpm

These packages are GPG signed by Red Hat, Inc. for security.  Our key
is available at:
     http://www.Red Hat.com/corp/contact.html

You can verify each package with the following command:
    rpm --checksig  

If you only wish to verify that each package has not been corrupted or
tampered with, examine only the md5sum with the following command:
    rpm --checksig --nogpg 

8. References:
 
http://www.securityfocus.com/bid/2205 
http://bugs.php.net/bugs-php3.php?id=7719


Copyright(c) 2000, 2001 Red Hat, Inc.


 
< Prev   Next >
    
Partner

 

Latest Features
Peter Smith Releases Linux Network Security Online
Securing a Linux Web Server
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Demystifying the Chinese Hacking Industry: Earning 6 Million a Night
Free Online security course (LearnSIA) - A Call for Help
What You Need to Know About Linux Rootkits
Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition
Yesterday's Edition
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2014 Guardian Digital, Inc. All rights reserved.