Aviso de seguridad de Debian

DSA-729-1 php4 -- olvido de sanear la entrada

Fecha del informe:
26 de may de 2005
Paquetes afectados:
php4
Vulnerable:
Referencias a bases de datos de seguridad:
En el sistema de seguimiento de errores de Debian: error 302701.
En el diccionario CVE de Mitre: CVE-2005-0525.
Información adicional:

Un investigador de iDEFENSE descubrió dos problemas en las funciones de procesamiento de imágenes de PHP, un lenguaje de guiones incrustado en el código HTML e interpretado en el servidor. Uno de los errores también estaba presente en woody. Al leer una imagen JPEG, a PHP se le podía engañar para que entrase en un bucle infinito debido a una validación insuficiente de la entrada.

Para la distribución estable (woody), este problema se ha corregido en la versión 4.1.2-7.woody4.

Para la distribución en pruebas (sarge), estos problemas se han corregido en la versión 4.3.10-10.

Para la distribución inestable (sid), estos problemas se han corregido en la versión 4.3.10-10.

Le recomendamos que actualice los paquetes de php4.

Arreglado en:

Debian GNU/Linux 3.0 (woody)

Fuentes:
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4.dsc
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4.diff.gz
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2.orig.tar.gz
Componentes independientes de la arquitectura:
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.1.2-7.woody4_all.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pear_4.1.2-7.woody4_all.deb
Alpha:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_sparc.deb

Las sumas MD5 de los ficheros que se listan están disponibles en el aviso original.