Aviso de seguridad de Debian
DSA-1206-1 php4 -- varias vulnerabilidades
- Fecha del informe:
- 6 de nov de 2006
- Paquetes afectados:
- php4
- Vulnerable:
- Sí
- Referencias a bases de datos de seguridad:
- En el diccionario CVE de Mitre: CVE-2005-3353, CVE-2006-3017, CVE-2006-4482, CVE-2006-5465.
- Información adicional:
-
Se han descubierto varias vulnerabilidades remotas en PHP, un lenguaje para guiones del lado del servidor que se incrusta en el HTML, que podía producir la ejecución de código arbitrario. El proyecto Common Vulnerabilities and Exposures identifica los siguientes problemas:
- CVE-2005-3353
Tim Starling descubrió que no se saneaba la entrada en el módulo EXIF, lo que podía conducir a una denegación de servicio.
- CVE-2006-3017
Stefan Esser descubrió un error de programación de seguridad crítica en la implementación de la tabla hash del motor Zend interno.
- CVE-2006-4482
Se descubrió que las funciones str_repeat() y wordwrap() no realizaban comprobaciones suficientes de los límites del búfer en sistemas de 64 bits, lo que podía conducir a la ejecución de código arbitrario.
- CVE-2006-5465
Stefan Esser descubrió un desbordamiento de búfer en htmlspecialchars() y htmlentities(), lo que podía conducir a la ejecución de código arbitrario.
Para la distribución estable (sarge), estos problemas se han corregido en la versión 4:4.3.10-18. Las compilaciones de hppa y m68k se proporcionarán en cuanto estén disponibles.
Para la distribución inestable (sid), estos problemas se han corregido en la versión 4:4.4.4-4 de php4 y en la versión 5.1.6-6 de php5.
Le recomendamos que actualice los paquetes de php4.
- CVE-2005-3353
- Arreglado en:
-
Debian GNU/Linux 3.1 (sarge)
- Fuentes:
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-18.dsc
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-18.diff.gz
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10.orig.tar.gz
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-18.diff.gz
- Componentes independientes de la arquitectura:
- http://security.debian.org/pool/updates/main/p/php4/php4-pear_4.3.10-18_all.deb
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-18_all.deb
- http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-18_all.deb
- Alpha:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_alpha.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_alpha.deb
- AMD64:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_amd64.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_amd64.deb
- ARM:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_arm.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_i386.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_ia64.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_ia64.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_mips.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_mipsel.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_powerpc.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_s390.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-18_sparc.deb
- http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-18_sparc.deb
Las sumas MD5 de los ficheros que se listan están disponibles en el aviso original.