Slackware 10.0 / 10.1 / 8.1 / 9.0 / 9.1 / current : PHP (SSA:2005-242-02)

This script is Copyright (C) 2005-2013 Tenable Network Security, Inc.


Synopsis :

The remote Slackware host is missing a security update.

Description :

New PHP packages are available for Slackware 8.1, 9.0, 9.1, 10.0,
10.1, and -current to fix security issues. PHP has been relinked with
the shared PCRE library to fix an overflow issue with PHP's builtin
PRCE code, and PEAR::XMLRPC has been upgraded to version 1.4.0 which
eliminates the eval() function. The eval() function is believed to be
insecure as implemented, and would be difficult to secure. Note that
these new packages now require that the PCRE package be installed, so
be sure to get the new package from the patches/packages/ directory if
you don't already have it. A new version of this (6.3) was also issued
today, so be sure that is the one you install.

See also :

http://www.nessus.org/u?3f72b2a9

Solution :

Update the affected php package.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)

Family: Slackware Local Security Checks

Nessus Plugin ID: 19859 ()

Bugtraq ID:

CVE ID: CVE-2005-2491
CVE-2005-2498