Ubuntu Security Notice (C) 2012-2014 Canonical, Inc. / NASL script (C) 2012-2014 Tenable Network Security, Inc.
The remote Ubuntu host is missing a security-related patch.
It was discovered that PHP incorrectly handled certain character
sequences when applying HTTP response-splitting protection. A remote
attacker could create a specially crafted URL and inject arbitrary
headers. (CVE-2011-1398, CVE-2012-4388)
It was discovered that PHP incorrectly handled directories with a
large number of files. This could allow a remote attacker to execute
arbitrary code with the privileges of the web server, or to perform a
denial of service. (CVE-2012-2688)
It was discovered that PHP incorrectly parsed certain PDO prepared
statements. A remote attacker could use this flaw to cause PHP to
crash, leading to a denial of service. (CVE-2012-3450).
Update the affected php5 package.
Risk factor :
Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 7.8
Public Exploit Available : true