Aviso de seguridad de Debian

DSA-1282-1 php4 -- varias vulnerabilidades

Fecha del informe:
26 de abr de 2007
Paquetes afectados:
php4
Vulnerable:
Referencias a bases de datos de seguridad:
En el diccionario CVE de Mitre: CVE-2007-1286, CVE-2007-1380, CVE-2007-1521, CVE-2007-1711, CVE-2007-1718, CVE-2007-1777.
Información adicional:

Se han descubierto varias vulnerabilidades remotas en PHP, un lenguaje de guiones incrustados en HTML del lado del servidor, que podían producir la ejecución de código arbitrario. El proyecto Common Vulnerabilities and Exposures ha identificado los siguientes problemas:

  • CVE-2007-1286

    Stefan Esser descubrió un desbordamiento en el código de gestión de referencia a objeto en la función unserialize(), que permitía la ejecución de código arbitrario se se pasaba una entrada mal formada desde una aplicación.

  • CVE-2007-1380

    Stefan Esser descubrió que el manipulador de la sesión no realizaba una validación suficiente de los valores de longitud del nombre de la variable, lo que permitía la revelación de información mediante una debilidad de información en el montón.

  • CVE-2007-1521

    Stefan Esser descubrió una vulnerabilidad de doble liberación en la función session_regenerate_id(), que permitía la ejecución de código arbitrario.

  • CVE-2007-1711

    Stefan Esser descubrió una vulnerabilidad de doble liberación en el código de gestión de la sesión, que permitía la ejecución de código arbitrario.

  • CVE-2007-1718

    Stefan Esser descubrió que la función mail() no realizaba una validación suficiente de las cabeceras plegadas de los correos, lo que permitía una inyección de encabezados de correo.

  • CVE-2007-1777

    Stefan Esser descubrió que la extensión para gestionar archivos ZIO no realizaba suficientes comprobaciones de la longitud, lo que permitía la ejecución de código arbitrario.

Para la distribución estable anterior (sarge), estos problemas se han corregido en la versión 4.3.10-20.

Para la distribución estable (etch), estos problemas se han corregido en la versión 4.4.4-8+etch2.

Para la distribución inestable (sid), estos problemas se han corregido en la versión 4.4.6-1. php4 se eliminará de sid, por lo que se le recomienda que migre a php5 si quiere permanecer con la distribución inestable.

Le recomendamos que actualice los paquetes de PHP. Aún no están disponibles los paquetes para las arquitecturas arm, m68k, mips y mipsel. Se proporcionarán más adelante.

Arreglado en:

Debian GNU/Linux 3.1 (sarge)

Fuentes:
http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-20.dsc
http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-20.diff.gz
http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10.orig.tar.gz
Componentes independientes de la arquitectura:
http://security.debian.org/pool/updates/main/p/php4/php4-pear_4.3.10-20_all.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.3.10-20_all.deb
Alpha:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-20_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-20_alpha.deb
AMD64:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-20_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-20_amd64.deb
HPPA:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-20_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-20_hppa.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-20_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-20_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-20_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-20_ia64.deb
PowerPC:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-20_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-20_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-20_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-20_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.3.10-20_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.3.10-20_sparc.deb

Debian GNU/Linux 4.0 (etch)

Fuentes:
http://security.debian.org/pool/updates/main/p/php4/php4_4.4.4-8+etch2.dsc
http://security.debian.org/pool/updates/main/p/php4/php4_4.4.4-8+etch2.diff.gz
http://security.debian.org/pool/updates/main/p/php4/php4_4.4.4.orig.tar.gz
Componentes independientes de la arquitectura:
http://security.debian.org/pool/updates/main/p/php4/php4-pear_4.4.4-8+etch2_all.deb
http://security.debian.org/pool/updates/main/p/php4/php4_4.4.4-8+etch2_all.deb
Alpha:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcrypt_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pgsql_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pspell_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.4.4-8+etch2_alpha.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.4.4-8+etch2_alpha.deb
AMD64:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-interbase_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcrypt_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pgsql_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pspell_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.4.4-8+etch2_amd64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.4.4-8+etch2_amd64.deb
HPPA:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcrypt_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pgsql_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pspell_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.4.4-8+etch2_hppa.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.4.4-8+etch2_hppa.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-interbase_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcrypt_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pgsql_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pspell_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.4.4-8+etch2_i386.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.4.4-8+etch2_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcrypt_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pgsql_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pspell_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.4.4-8+etch2_ia64.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.4.4-8+etch2_ia64.deb
PowerPC:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcrypt_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pgsql_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pspell_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.4.4-8+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.4.4-8+etch2_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcrypt_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pgsql_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pspell_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.4.4-8+etch2_s390.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.4.4-8+etch2_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/p/php4/libapache-mod-php4_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/libapache2-mod-php4_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cgi_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-cli_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-common_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-curl_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-dev_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-domxml_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-gd_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-imap_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-ldap_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcal_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mcrypt_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mhash_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-mysql_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-odbc_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pgsql_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-pspell_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-recode_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-snmp_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-sybase_4.4.4-8+etch2_sparc.deb
http://security.debian.org/pool/updates/main/p/php4/php4-xslt_4.4.4-8+etch2_sparc.deb

Las sumas MD5 de los ficheros que se listan están disponibles en el aviso original.