Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: Php: Denial of Service
Posted by Benjamin D. Thomas
exploited by malicious people to cause a DoS (Denial of Service).
--==============21092842=Content-Type: multipart/alternative; boundary 1636c9240c134440046d2c8168
--001636c9240c134440046d2c8168
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
------------------------------------------------------------------------
Pardus Linux Security Advisory 2009-96 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2009-06-25
Severity: 2
Type: Remote
------------------------------------------------------------------------
Summary
======
A vulnerability has been reported in PHP, which can potentially be
exploited by malicious people to cause a DoS (Denial of Service).
Description
==========
The vulnerability is caused due to an input validation error in the
"exif_read_data()" function, which can be exploited to cause a crash
when a specially crafted jpg image is being processed.
Affected packages:
Pardus 2008:
mod_php, all before 5.2.10-69-9
php-cli, all before 5.2.10-69-9
php-common, all before 5.2.10-69-9
Resolution
=========
There are update(s) for mod_php, php-cli, php-common. You can update
them via Package Manager or with a single command from console:
pisi up mod_php php-cli php-common
References
=========
* http://bugs.pardus.org.tr/show_bug.cgi?id062
* http://www.php.net/releases/5_2_10.php
* http://secunia.com/advisories/35441/