`

---------------------------------------------------------------------
                   Red Hat, Inc. Red Hat Security Advisory

Synopsis:          Updated PHP packages available for Red Hat Linux 5.2, 6.x,
and 7
Advisory ID:       RHSA-2000:136-10
Issue date:        2000-12-20
Updated on:        2001-01-24
Product:           Red Hat Linux
Keywords:          php multipart gd engine
Cross references:  RHSA-2000:88 RHBA-2000:112
Obsoletes:         
---------------------------------------------------------------------

1. Topic:

Updated PHP packages are now available for Red Hat Linux 5.2, 6.x, and 7.

2. Relevant releases/architectures:

Red Hat Linux 5.2 - alpha, i386, sparc

Red Hat Linux 6.0 - i386, sparc

Red Hat Linux 6.1 - alpha, i386, sparc

Red Hat Linux 6.2 - alpha, i386, sparc

Red Hat Linux 7.0 - alpha, i386

3. Problem description:

Clients uploading "multipart/form-data" information with form requests
could cause PHP 3.0.17 to crash.  The GD module was not compiled into the
previously-issued PHP 4.0.3pl1 errata packages.  The php-mysql package is
linked against an older version of the libmysqlclient shared library, which
was obsoleted by a previous MySQL errata.  Security holes in versions 4.0.0
through 4.0.4 of the PHP Apache module have been found.

4. Solution:

Because of dependencies, the packages must be installed as a group.

After downloading all RPMs needed for your particular architecture, run:

rpm -Fvh php*

Then restart your web server:

/etc/rc.d/init.d/httpd restart

5. Bug IDs fixed  (  for more info):

19906 - PHP 3.0.17-1.6.2 crashes apache reproducable
21291 - php should be rebuild on new environment
21620 - configure option --enable-wddx not used
21664 - updated Red Hat 7 PHP rpm's broken
22376 - php-4.0.3pl1 from 7.0 errata fails to install gd.so ld
23690 - php-mysql needs rebuild in light of mysql-3.23.29-1
23902 - PHP4.0.4pl1 solve 2 security problems

6. RPMs required:

Red Hat Linux 5.2:

SRPMS: 
 

alpha: 
  
  
 

i386: 
  
  
 

sparc: 
  
  
 

Red Hat Linux 6.0:

SRPMS: 
 

i386: 
  
  
  
  
 

sparc: 
  
  
  
  
 

Red Hat Linux 6.1:

SRPMS: 
 

alpha: 
  
  
  
  
 

i386: 
  
  
  
  
 

sparc: 
  
  
  
  
 

Red Hat Linux 6.2:

SRPMS: 
 

alpha: 
  
  
  
  
 

i386: 
  
  
  
  
 

sparc: 
  
  
  
  
 

Red Hat Linux 7.0:

SRPMS: 
 

alpha: 
  
  
  
  
  
 

i386: 
  
  
  
  
  
 



7. Verification:

MD5 sum                           Package Name
--------------------------------------------------------------------------
fd62a3d0460fb6442d01f661e95275ab  5.2/SRPMS/php-3.0.18-1.5.x.src.rpm
625d416b98954143c0736dfd2143831b  5.2/alpha/php-3.0.18-1.5.x.alpha.rpm
5434b59b75a0227068b15175dbae3e1c  5.2/alpha/php-manual-3.0.18-1.5.x.alpha.rpm
6ee3385d9e4e7e0308e14d437bf197a9  5.2/alpha/php-pgsql-3.0.18-1.5.x.alpha.rpm
c9c2f6e2202519c204886cb01bbc5170  5.2/i386/php-3.0.18-1.5.x.i386.rpm
e2047b5a28cc6ec9c987a7c168d57bab  5.2/i386/php-manual-3.0.18-1.5.x.i386.rpm
3880561630fbb66dcc8432601010904d  5.2/i386/php-pgsql-3.0.18-1.5.x.i386.rpm
913fcfeec79c5c9ee57d76c519f8e652  5.2/sparc/php-3.0.18-1.5.x.sparc.rpm
27f4790a441e0661322a54082e067699  5.2/sparc/php-manual-3.0.18-1.5.x.sparc.rpm
a81d8e856451349c7b9b9b0597aa97ad  5.2/sparc/php-pgsql-3.0.18-1.5.x.sparc.rpm
f135fa49dee86cb2fd9aba665cda64d1  6.0/SRPMS/php-3.0.18-1.6.x.src.rpm
13998f321e1787af7bac4f01e9e01b81  6.0/i386/php-3.0.18-1.6.x.i386.rpm
d7a6f3e9d64c1edbeb10a1170e0d90b2  6.0/i386/php-imap-3.0.18-1.6.x.i386.rpm
bd3d6c413faf3ca0e271c7195fe5c2b1  6.0/i386/php-ldap-3.0.18-1.6.x.i386.rpm
9e19cc6e58fbeff7095abcd02120174f  6.0/i386/php-manual-3.0.18-1.6.x.i386.rpm
adf510253a012e01d0cc1bb631fd423f  6.0/i386/php-pgsql-3.0.18-1.6.x.i386.rpm
9f54bf780fbef67a03d7065a6d69f762  6.0/sparc/php-3.0.18-1.6.x.sparc.rpm
d17460149d0375a991773bf6f296957a  6.0/sparc/php-imap-3.0.18-1.6.x.sparc.rpm
d4c00495db0fbb0014697afc25cc3eca  6.0/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm
9ffb47a272984fd2757e09747e859695  6.0/sparc/php-manual-3.0.18-1.6.x.sparc.rpm
09acd6bbd4c19a57c0bbf64fcd64f2b8  6.0/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm
f135fa49dee86cb2fd9aba665cda64d1  6.1/SRPMS/php-3.0.18-1.6.x.src.rpm
ce0b8c6d8be5db195b70c3631e75e200  6.1/alpha/php-3.0.18-1.6.x.alpha.rpm
42e64510ed0fcce493cc20181eafd419  6.1/alpha/php-imap-3.0.18-1.6.x.alpha.rpm
53ac23e30083ae09d3a0aee04039e666  6.1/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm
39491a3833a9bd926b81fdc500e9a39f  6.1/alpha/php-manual-3.0.18-1.6.x.alpha.rpm
85aeccf83a08e9d69c5464c17fc9c445  6.1/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm
13998f321e1787af7bac4f01e9e01b81  6.1/i386/php-3.0.18-1.6.x.i386.rpm
d7a6f3e9d64c1edbeb10a1170e0d90b2  6.1/i386/php-imap-3.0.18-1.6.x.i386.rpm
bd3d6c413faf3ca0e271c7195fe5c2b1  6.1/i386/php-ldap-3.0.18-1.6.x.i386.rpm
9e19cc6e58fbeff7095abcd02120174f  6.1/i386/php-manual-3.0.18-1.6.x.i386.rpm
adf510253a012e01d0cc1bb631fd423f  6.1/i386/php-pgsql-3.0.18-1.6.x.i386.rpm
9f54bf780fbef67a03d7065a6d69f762  6.1/sparc/php-3.0.18-1.6.x.sparc.rpm
d17460149d0375a991773bf6f296957a  6.1/sparc/php-imap-3.0.18-1.6.x.sparc.rpm
d4c00495db0fbb0014697afc25cc3eca  6.1/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm
9ffb47a272984fd2757e09747e859695  6.1/sparc/php-manual-3.0.18-1.6.x.sparc.rpm
09acd6bbd4c19a57c0bbf64fcd64f2b8  6.1/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm
f135fa49dee86cb2fd9aba665cda64d1  6.2/SRPMS/php-3.0.18-1.6.x.src.rpm
ce0b8c6d8be5db195b70c3631e75e200  6.2/alpha/php-3.0.18-1.6.x.alpha.rpm
42e64510ed0fcce493cc20181eafd419  6.2/alpha/php-imap-3.0.18-1.6.x.alpha.rpm
53ac23e30083ae09d3a0aee04039e666  6.2/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm
39491a3833a9bd926b81fdc500e9a39f  6.2/alpha/php-manual-3.0.18-1.6.x.alpha.rpm
85aeccf83a08e9d69c5464c17fc9c445  6.2/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm
13998f321e1787af7bac4f01e9e01b81  6.2/i386/php-3.0.18-1.6.x.i386.rpm
d7a6f3e9d64c1edbeb10a1170e0d90b2  6.2/i386/php-imap-3.0.18-1.6.x.i386.rpm
bd3d6c413faf3ca0e271c7195fe5c2b1  6.2/i386/php-ldap-3.0.18-1.6.x.i386.rpm
9e19cc6e58fbeff7095abcd02120174f  6.2/i386/php-manual-3.0.18-1.6.x.i386.rpm
adf510253a012e01d0cc1bb631fd423f  6.2/i386/php-pgsql-3.0.18-1.6.x.i386.rpm
9f54bf780fbef67a03d7065a6d69f762  6.2/sparc/php-3.0.18-1.6.x.sparc.rpm
d17460149d0375a991773bf6f296957a  6.2/sparc/php-imap-3.0.18-1.6.x.sparc.rpm
d4c00495db0fbb0014697afc25cc3eca  6.2/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm
9ffb47a272984fd2757e09747e859695  6.2/sparc/php-manual-3.0.18-1.6.x.sparc.rpm
09acd6bbd4c19a57c0bbf64fcd64f2b8  6.2/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm
fc2f89fb24cdcae8485a334f2e0f2372  7.0/SRPMS/php-4.0.4pl1-3.src.rpm
4f7b7d6c57c3d58595b394a6b69b0830  7.0/alpha/php-4.0.4pl1-3.alpha.rpm
bc11c5346d930ac12236856b8c64f33c  7.0/alpha/php-imap-4.0.4pl1-3.alpha.rpm
8d98cdcf391c251d96685d5dce7fe588  7.0/alpha/php-ldap-4.0.4pl1-3.alpha.rpm
92ad775f67ff1d74fae764aa592e1103  7.0/alpha/php-manual-4.0.4pl1-3.alpha.rpm
26b438a4f276cbdec1a22591214f4ad6  7.0/alpha/php-mysql-4.0.4pl1-3.alpha.rpm
ef1cd2ed0bf74a2dd491fe34c686f8b5  7.0/alpha/php-pgsql-4.0.4pl1-3.alpha.rpm
2946e063efcb2be68f789624168b1a8b  7.0/i386/php-4.0.4pl1-3.i386.rpm
fdb049b4572bff635b5327cdbfae1266  7.0/i386/php-imap-4.0.4pl1-3.i386.rpm
4408734b5dd1c60d325d95216999f938  7.0/i386/php-ldap-4.0.4pl1-3.i386.rpm
502a66f4e11d98cd3f266bd1f897f9d7  7.0/i386/php-manual-4.0.4pl1-3.i386.rpm
066bcf976c3f930d16f191813473218c  7.0/i386/php-mysql-4.0.4pl1-3.i386.rpm
1660362c37dd4b603aa733f2d92c2e94  7.0/i386/php-pgsql-4.0.4pl1-3.i386.rpm

These packages are GPG signed by Red Hat, Inc. for security.  Our key
is available at:
      

You can verify each package with the following command:
    rpm --checksig  

If you only wish to verify that each package has not been corrupted or
tampered with, examine only the md5sum with the following command:
    rpm --checksig --nogpg 

8. References:
 
 
 


Copyright(c) 2000, 2001 Red Hat, Inc.


`

Red Hat: 'php' updates

This update fixes several general problems with php3 and 4, along with some security holes in versions 4.0 through 4.0.4 of php.

Summary



Summary

Clients uploading "multipart/form-data" information with form requestscould cause PHP 3.0.17 to crash. The GD module was not compiled into thepreviously-issued PHP 4.0.3pl1 errata packages. The php-mysql package islinked against an older version of the libmysqlclient shared library, whichwas obsoleted by a previous MySQL errata. Security holes in versions 4.0.0through 4.0.4 of the PHP Apache module have been found.


Solution

Because of dependencies, the packages must be installed as a group.
After downloading all RPMs needed for your particular architecture, run:
rpm -Fvh php*
Then restart your web server:
/etc/rc.d/init.d/httpd restart
5. Bug IDs fixed ( for more info):
19906 - PHP 3.0.17-1.6.2 crashes apache reproducable 21291 - php should be rebuild on new environment 21620 - configure option --enable-wddx not used 21664 - updated Red Hat 7 PHP rpm's broken 22376 - php-4.0.3pl1 from 7.0 errata fails to install gd.so ld 23690 - php-mysql needs rebuild in light of mysql-3.23.29-1 23902 - PHP4.0.4pl1 solve 2 security problems
6. RPMs required:
Red Hat Linux 5.2:
SRPMS:

alpha:



i386:



sparc:



Red Hat Linux 6.0:
SRPMS:

i386:





sparc:





Red Hat Linux 6.1:
SRPMS:

alpha:





i386:





sparc:





Red Hat Linux 6.2:
SRPMS:

alpha:





i386:





sparc:





Red Hat Linux 7.0:
SRPMS:

alpha:






i386:








7. Verification:
MD5 sum Package Name fd62a3d0460fb6442d01f661e95275ab 5.2/SRPMS/php-3.0.18-1.5.x.src.rpm 625d416b98954143c0736dfd2143831b 5.2/alpha/php-3.0.18-1.5.x.alpha.rpm 5434b59b75a0227068b15175dbae3e1c 5.2/alpha/php-manual-3.0.18-1.5.x.alpha.rpm 6ee3385d9e4e7e0308e14d437bf197a9 5.2/alpha/php-pgsql-3.0.18-1.5.x.alpha.rpm c9c2f6e2202519c204886cb01bbc5170 5.2/i386/php-3.0.18-1.5.x.i386.rpm e2047b5a28cc6ec9c987a7c168d57bab 5.2/i386/php-manual-3.0.18-1.5.x.i386.rpm 3880561630fbb66dcc8432601010904d 5.2/i386/php-pgsql-3.0.18-1.5.x.i386.rpm 913fcfeec79c5c9ee57d76c519f8e652 5.2/sparc/php-3.0.18-1.5.x.sparc.rpm 27f4790a441e0661322a54082e067699 5.2/sparc/php-manual-3.0.18-1.5.x.sparc.rpm a81d8e856451349c7b9b9b0597aa97ad 5.2/sparc/php-pgsql-3.0.18-1.5.x.sparc.rpm f135fa49dee86cb2fd9aba665cda64d1 6.0/SRPMS/php-3.0.18-1.6.x.src.rpm 13998f321e1787af7bac4f01e9e01b81 6.0/i386/php-3.0.18-1.6.x.i386.rpm d7a6f3e9d64c1edbeb10a1170e0d90b2 6.0/i386/php-imap-3.0.18-1.6.x.i386.rpm bd3d6c413faf3ca0e271c7195fe5c2b1 6.0/i386/php-ldap-3.0.18-1.6.x.i386.rpm 9e19cc6e58fbeff7095abcd02120174f 6.0/i386/php-manual-3.0.18-1.6.x.i386.rpm adf510253a012e01d0cc1bb631fd423f 6.0/i386/php-pgsql-3.0.18-1.6.x.i386.rpm 9f54bf780fbef67a03d7065a6d69f762 6.0/sparc/php-3.0.18-1.6.x.sparc.rpm d17460149d0375a991773bf6f296957a 6.0/sparc/php-imap-3.0.18-1.6.x.sparc.rpm d4c00495db0fbb0014697afc25cc3eca 6.0/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm 9ffb47a272984fd2757e09747e859695 6.0/sparc/php-manual-3.0.18-1.6.x.sparc.rpm 09acd6bbd4c19a57c0bbf64fcd64f2b8 6.0/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm f135fa49dee86cb2fd9aba665cda64d1 6.1/SRPMS/php-3.0.18-1.6.x.src.rpm ce0b8c6d8be5db195b70c3631e75e200 6.1/alpha/php-3.0.18-1.6.x.alpha.rpm 42e64510ed0fcce493cc20181eafd419 6.1/alpha/php-imap-3.0.18-1.6.x.alpha.rpm 53ac23e30083ae09d3a0aee04039e666 6.1/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm 39491a3833a9bd926b81fdc500e9a39f 6.1/alpha/php-manual-3.0.18-1.6.x.alpha.rpm 85aeccf83a08e9d69c5464c17fc9c445 6.1/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm 13998f321e1787af7bac4f01e9e01b81 6.1/i386/php-3.0.18-1.6.x.i386.rpm d7a6f3e9d64c1edbeb10a1170e0d90b2 6.1/i386/php-imap-3.0.18-1.6.x.i386.rpm bd3d6c413faf3ca0e271c7195fe5c2b1 6.1/i386/php-ldap-3.0.18-1.6.x.i386.rpm 9e19cc6e58fbeff7095abcd02120174f 6.1/i386/php-manual-3.0.18-1.6.x.i386.rpm adf510253a012e01d0cc1bb631fd423f 6.1/i386/php-pgsql-3.0.18-1.6.x.i386.rpm 9f54bf780fbef67a03d7065a6d69f762 6.1/sparc/php-3.0.18-1.6.x.sparc.rpm d17460149d0375a991773bf6f296957a 6.1/sparc/php-imap-3.0.18-1.6.x.sparc.rpm d4c00495db0fbb0014697afc25cc3eca 6.1/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm 9ffb47a272984fd2757e09747e859695 6.1/sparc/php-manual-3.0.18-1.6.x.sparc.rpm 09acd6bbd4c19a57c0bbf64fcd64f2b8 6.1/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm f135fa49dee86cb2fd9aba665cda64d1 6.2/SRPMS/php-3.0.18-1.6.x.src.rpm ce0b8c6d8be5db195b70c3631e75e200 6.2/alpha/php-3.0.18-1.6.x.alpha.rpm 42e64510ed0fcce493cc20181eafd419 6.2/alpha/php-imap-3.0.18-1.6.x.alpha.rpm 53ac23e30083ae09d3a0aee04039e666 6.2/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm 39491a3833a9bd926b81fdc500e9a39f 6.2/alpha/php-manual-3.0.18-1.6.x.alpha.rpm 85aeccf83a08e9d69c5464c17fc9c445 6.2/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm 13998f321e1787af7bac4f01e9e01b81 6.2/i386/php-3.0.18-1.6.x.i386.rpm d7a6f3e9d64c1edbeb10a1170e0d90b2 6.2/i386/php-imap-3.0.18-1.6.x.i386.rpm bd3d6c413faf3ca0e271c7195fe5c2b1 6.2/i386/php-ldap-3.0.18-1.6.x.i386.rpm 9e19cc6e58fbeff7095abcd02120174f 6.2/i386/php-manual-3.0.18-1.6.x.i386.rpm adf510253a012e01d0cc1bb631fd423f 6.2/i386/php-pgsql-3.0.18-1.6.x.i386.rpm 9f54bf780fbef67a03d7065a6d69f762 6.2/sparc/php-3.0.18-1.6.x.sparc.rpm d17460149d0375a991773bf6f296957a 6.2/sparc/php-imap-3.0.18-1.6.x.sparc.rpm d4c00495db0fbb0014697afc25cc3eca 6.2/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm 9ffb47a272984fd2757e09747e859695 6.2/sparc/php-manual-3.0.18-1.6.x.sparc.rpm 09acd6bbd4c19a57c0bbf64fcd64f2b8 6.2/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm fc2f89fb24cdcae8485a334f2e0f2372 7.0/SRPMS/php-4.0.4pl1-3.src.rpm 4f7b7d6c57c3d58595b394a6b69b0830 7.0/alpha/php-4.0.4pl1-3.alpha.rpm bc11c5346d930ac12236856b8c64f33c 7.0/alpha/php-imap-4.0.4pl1-3.alpha.rpm 8d98cdcf391c251d96685d5dce7fe588 7.0/alpha/php-ldap-4.0.4pl1-3.alpha.rpm 92ad775f67ff1d74fae764aa592e1103 7.0/alpha/php-manual-4.0.4pl1-3.alpha.rpm 26b438a4f276cbdec1a22591214f4ad6 7.0/alpha/php-mysql-4.0.4pl1-3.alpha.rpm ef1cd2ed0bf74a2dd491fe34c686f8b5 7.0/alpha/php-pgsql-4.0.4pl1-3.alpha.rpm 2946e063efcb2be68f789624168b1a8b 7.0/i386/php-4.0.4pl1-3.i386.rpm fdb049b4572bff635b5327cdbfae1266 7.0/i386/php-imap-4.0.4pl1-3.i386.rpm 4408734b5dd1c60d325d95216999f938 7.0/i386/php-ldap-4.0.4pl1-3.i386.rpm 502a66f4e11d98cd3f266bd1f897f9d7 7.0/i386/php-manual-4.0.4pl1-3.i386.rpm 066bcf976c3f930d16f191813473218c 7.0/i386/php-mysql-4.0.4pl1-3.i386.rpm 1660362c37dd4b603aa733f2d92c2e94 7.0/i386/php-pgsql-4.0.4pl1-3.i386.rpm
These packages are GPG signed by Red Hat, Inc. for security. Our key is available at:

You can verify each package with the following command: rpm --checksig
If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg

References

Copyright(c) 2000, 2001 Red Hat, Inc. `

Package List


Severity
Advisory ID: RHSA-2000:136-10
Issued Date: : 2000-12-20
Updated on: 2001-01-24
Product: Red Hat Linux
Keywords: php multipart gd engine
Cross references: RHSA-2000:88 RHBA-2000:112
Obsoletes:

Topic


Topic

Updated PHP packages are now available for Red Hat Linux 5.2, 6.x, and 7.


 

Relevant Releases Architectures

Red Hat Linux 5.2 - alpha, i386, sparc

Red Hat Linux 6.0 - i386, sparc

Red Hat Linux 6.1 - alpha, i386, sparc

Red Hat Linux 6.2 - alpha, i386, sparc

Red Hat Linux 7.0 - alpha, i386


Bugs Fixed


Related News