Aviso de seguridad de Debian

DSA-531-1 php4 -- varias vulnerabilidades

Fecha del informe:
20 de jul de 2004
Paquetes afectados:
php4
Vulnerable:
Referencias a bases de datos de seguridad:
En el diccionario CVE de Mitre: CVE-2004-0594, CVE-2004-0595.
Información adicional:

Se descubrieron dos vulnerabilidades en php4:

  • CAN-2004-0594

    La funcionalidad memory_limit de PHP 4.x hasta la 4.37 y 5.x hasta la 5.0.0RC3, bajo ciertas condiciones como que register_globals estuviera activado, permitía a los atacantes remotos ejecutar código arbitrario provocando que se abortara memory_limit durante la ejecución de la función zend_hash_init y sobreescribiendo un puntero del destructor HashTable antes de completar la inicialización de las estructuras de datos clave.

  • CAN-2004-0595

    La función strip_tags de PHP 4.x hasta la 4.3.7, y 5.x hasta la 5.0.0RC3, no filtraba los caracteres nulos (\0) de los nombres de las etiquetas cuando se restringían las entradas a las etiquetas admisibles, permitiendo que navegadores web como Internet Explorer y Safari procesaran etiquetas peligrosas. Los navegadores citados antes ignoran los caracteres nulos y facilitan la explotación de vulnerabilidades de guiones a través del sitio (XSS).

Para la distribución estable actual (woody), estos problemas se han corregido en la versión 4.1.2-7.

Para la distribución inestable (sid), estos problemas se han corregido en la versión 4:4.3.8-1.

Le recomendamos que actualice el paquete php4.

Arreglado en:

Debian GNU/Linux 3.0 (woody)

Fuentes:
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.dsc
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.diff.gz
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2.orig.tar.gz
Componentes independientes de la arquitectura:
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.1.2-7_all.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pear_4.1.2-7_all.deb
Alpha:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7_arm.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7.0.1_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7.0.1_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7_m68k.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7_mips.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7_mipsel.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/p/php4/caudium-php4_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.1.2-7_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.1.2-7_sparc.deb

Las sumas MD5 de los ficheros que se listan están disponibles en el aviso original.