Slackware 10.2 / current : PHP (SSA:2005-310-05)

This script is Copyright (C) 2005-2013 Tenable Network Security, Inc.


Synopsis :

The remote Slackware host is missing a security update.

Description :

New PHP packages are available for Slackware 10.2 and -current to fix
minor security issues relating to the overwriting of the GLOBALS
array. It has been reported here that this new version of PHP also
breaks squirrelmail and probably some other things. Given the vague
nature of the security report, it's possible that the cure might be
worse than the disease as far as this upgrade is concerned. If you
encounter problems, you may wish to drop back to 4.4.0, and I believe
that doing so is relatively safe. I understand at least some of the
issues are fixed in CVS already, so perhaps another maintainance
release is not far off. Thanks to Gerardo Exequiel Pozzi for bringing
the issues with 4.4.1 to my attention so that this additional
information could be included here.

See also :

http://www.nessus.org/u?ea24bace

Solution :

Update the affected php package.

Risk factor :

High

Family: Slackware Local Security Checks

Nessus Plugin ID: 20152 ()

Bugtraq ID:

CVE ID: