Slackware 10.2 / current : PHP (SSA:2005-310-05)

high Nessus Plugin ID 20152

Synopsis

The remote Slackware host is missing a security update.

Description

New PHP packages are available for Slackware 10.2 and -current to fix minor security issues relating to the overwriting of the GLOBALS array. It has been reported here that this new version of PHP also breaks squirrelmail and probably some other things. Given the vague nature of the security report, it's possible that the cure might be worse than the disease as far as this upgrade is concerned. If you encounter problems, you may wish to drop back to 4.4.0, and I believe that doing so is relatively safe. I understand at least some of the issues are fixed in CVS already, so perhaps another maintainance release is not far off. Thanks to Gerardo Exequiel Pozzi for bringing the issues with 4.4.1 to my attention so that this additional information could be included here.

Solution

Update the affected php package.

See Also

http://www.nessus.org/u?ea24bace

Plugin Details

Severity: High

ID: 20152

File Name: Slackware_SSA_2005-310-05.nasl

Version: 1.14

Type: local

Published: 11/7/2005

Updated: 1/14/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:slackware:slackware_linux:php, cpe:/o:slackware:slackware_linux, cpe:/o:slackware:slackware_linux:10.2

Required KB Items: Host/local_checks_enabled, Host/Slackware/release, Host/Slackware/packages

Patch Publication Date: 11/6/2005

Reference Information

SSA: 2005-310-05