CentOS 3 / 4 : php (CESA-2006:0568)

high Nessus Plugin ID 22037

Synopsis

The remote CentOS host is missing one or more security updates.

Description

Updated PHP packages that fix multiple security issues are now available for Red Hat Enterprise Linux 3 and 4.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Web server.

A directory traversal vulnerability was found in PHP. Local users could bypass open_basedir restrictions allowing remote attackers to create files in arbitrary directories via the tempnam() function.
(CVE-2006-1494)

The wordwrap() PHP function did not properly check for integer overflow in the handling of the 'break' parameter. An attacker who could control the string passed to the 'break' parameter could cause a heap overflow. (CVE-2006-1990)

A flaw was found in the zend_hash_del() PHP function. For PHP scripts that rely on the use of the unset() function, a remote attacker could force variable initialization to be bypassed. This would be a security issue particularly for installations that enable the 'register_globals' setting. 'register_globals' is disabled by default in Red Hat Enterprise Linux. (CVE-2006-3017)

Users of PHP should upgrade to these updated packages, which contain backported patches that resolve these issues.

Solution

Update the affected php packages.

See Also

http://www.nessus.org/u?b2b64d3f

http://www.nessus.org/u?d6851284

http://www.nessus.org/u?61c43641

http://www.nessus.org/u?953a8202

http://www.nessus.org/u?43eb7035

http://www.nessus.org/u?ef7a6b21

Plugin Details

Severity: High

ID: 22037

File Name: centos_RHSA-2006-0568.nasl

Version: 1.18

Type: local

Agent: unix

Published: 7/13/2006

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:centos:centos:php, p-cpe:/a:centos:centos:php-devel, p-cpe:/a:centos:centos:php-domxml, p-cpe:/a:centos:centos:php-gd, p-cpe:/a:centos:centos:php-imap, p-cpe:/a:centos:centos:php-ldap, p-cpe:/a:centos:centos:php-mbstring, p-cpe:/a:centos:centos:php-mysql, p-cpe:/a:centos:centos:php-ncurses, p-cpe:/a:centos:centos:php-odbc, p-cpe:/a:centos:centos:php-pear, p-cpe:/a:centos:centos:php-pgsql, p-cpe:/a:centos:centos:php-snmp, p-cpe:/a:centos:centos:php-xmlrpc, cpe:/o:centos:centos:3, cpe:/o:centos:centos:4

Required KB Items: Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

Patch Publication Date: 7/12/2006

Vulnerability Publication Date: 4/10/2006

Reference Information

CVE: CVE-2006-1494, CVE-2006-1990, CVE-2006-3017

RHSA: 2006:0568