Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian: 202301-15 Critical: Python Remote Code Execution Vulnerability

gentoo
Calendar Grey February 19, 2003
Dist Gentoo Esm H88
Gentoo Linux bulletin alerts users about a critical PHP vulnerability enabling arbitrary code execution. Immediate updates are essential to prevent exploits.
PHP contains code for preventing direct access to the CGI binary with configure option "--enable-force-cgi-redirect" and php.ini option "cgi.force_redirect".

Summary


- ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200302-09
- ---------------------------------------------------------------------
DATE    : 2003-02-19 13:28 UTC

- ---------------------------------------------------------------------
From release notes:
"PHP contains code for preventing direct access to the CGI binary with configure option "--enable-force-cgi-redirect" and php.ini option "cgi.force_redirect". In PHP 4.3.0 there is a bug which renders these options useless."
Read the full release notes at: PHP: PHP 4.3.1 Release Announcement
SOLUTION
It is recommended that all Gentoo Linux users who are running dev-php/mod_php and/or dev-php/php upgrade to php-4.3.1 and/or mod_php-4.3.1 as follows:
emerge sync emerge -u mod_php and/or emerge -u php emerge clean
- -----------------------...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : mod_php php
SUMMARY : arbitrary code execution
EXPLOIT : local

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here