Рекомендация Debian по безопасности

DSA-729-1 php4 -- отсутствие очистки ввода

Дата сообщения:
26.05.2005
Затронутые пакеты:
php4
Уязвим:
Да
Ссылки на базы данных по безопасности:
В системе отслеживания ошибок Debian: Ошибка 302701.
В каталоге Mitre CVE: CVE-2005-0525.
Более подробная информация:

Исследователь из iDEFENSE обнаружил две проблемы в функциях обработки изображений в PHP, серверном языке сценариев, встраиваемый в HTML, одна из которых присутствует и в woody. При чтении изображения в формате JPEG PHP может войти в бесконечный цикл из-за недостаточной проверки входных данных.

В стабильном выпуске (woody) эта проблема была исправлена в версии 4.1.2-7.woody4.

В тестируемом выпуске (sarge) эти проблемы были исправлены в версии 4.3.10-10.

В нестабильном выпуске (sid) эти проблемы были исправлены в версии 4.3.10-10.

Рекомендуется обновить пакеты php4.

Исправлено в:

Debian GNU/Linux 3.0 (woody)

Исходный код:
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4.dsc
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4.diff.gz
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2.orig.tar.gz
Независимые от архитектуры компоненты:
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.1.2-7.woody4_all.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pear_4.1.2-7.woody4_all.deb
Alpha:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.woody4_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.woody4_sparc.deb

Контрольные суммы MD5 этих файлов доступны в исходном сообщении.