Search:     Advanced search
server monitoring

SSA-2005-242-02 PHP

Article ID: 19859
Last updated: 27 Jan, 2009
Views: 392
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

SSA-2005-242-02 PHP

This script is Copyright (C) 2005 Tenable Network Security, Inc.

FamilySlackware Local Security Checks
Plugin ID19859
Bugtraq ID
CVE IDCVE-2005-2491
CVE-2005-2498

Description:

New PHP packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1,
and -current to fix security issues. PHP has been relinked with the
shared PCRE library to fix an overflow issue with PHPs builtin PRCE
code, and PEAR::XMLRPC has been upgraded to version 1.4.0 which
eliminates the eval() function. The eval() function is believed to be
insecure as implemented, and would be difficult to secure.

Note that these new packages now require that the PCRE package be
installed, so be sure to get the new package from the patches/packages/
directory if you dont already have it. A new version of this (6.3)
was also issued today, so be sure that is the one you install.

More details about these issues may be found in the Common
Vulnerabilities and Exposures (CVE) database:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2498

This article was:   Helpful | Not Helpful
Prev   Next
SSA-2005-283-01 xine-lib      SSA-2008-094-01 cups