Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.
http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html
http://secunia.com/advisories/25187
http://secunia.com/advisories/25191
http://secunia.com/advisories/25255
http://secunia.com/advisories/25445
http://secunia.com/advisories/25660
http://secunia.com/advisories/25938
http://secunia.com/advisories/25945
http://secunia.com/advisories/26048
http://secunia.com/advisories/26102
http://secunia.com/advisories/27377
http://security.gentoo.org/glsa/glsa-200705-19.xml
http://support.avaya.com/elmodocs2/security/ASA-2007-231.htm
http://us2.php.net/releases/4_4_7.php
http://us2.php.net/releases/5_2_2.php
http://www.debian.org/security/2007/dsa-1330
http://www.debian.org/security/2007/dsa-1331
http://www.mandriva.com/security/advisories?name=MDKSA-2007:102
http://www.mandriva.com/security/advisories?name=MDKSA-2007:103
http://www.redhat.com/support/errata/RHSA-2007-0349.html
http://www.redhat.com/support/errata/RHSA-2007-0355.html
http://www.securityfocus.com/bid/23813
http://www.securitytracker.com/id?1018024
http://www.trustix.org/errata/2007/0017/
http://www.ubuntu.com/usn/usn-485-1
http://www.vupen.com/english/advisories/2007/2187
https://issues.rpath.com/browse/RPL-1693
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11257
OR
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* versions from 5.1.0 to 5.1.6 (inclusive)
OR
OR
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
OR
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
78215 | F5 Networks BIG-IP : Multiple PHP vulnerabilities (SOL7859) | Nessus | F5 Networks Local Security Checks | high |
67497 | Oracle Linux 4 : php (ELSA-2007-0349) | Nessus | Oracle Linux Local Security Checks | high |
67496 | Oracle Linux 5 : php (ELSA-2007-0348) | Nessus | Oracle Linux Local Security Checks | high |
67050 | CentOS 4 : php (CESA-2007:0349) | Nessus | CentOS Local Security Checks | high |
29552 | SuSE 10 Security Update : PHP5 (ZYPP Patch Number 3754) | Nessus | SuSE Local Security Checks | high |
28086 | Ubuntu 6.06 LTS / 6.10 / 7.04 : php5 vulnerabilities (USN-485-1) | Nessus | Ubuntu Local Security Checks | high |
27392 | openSUSE 10 Security Update : php5 (php5-3753) | Nessus | SuSE Local Security Checks | high |
27391 | openSUSE 10 Security Update : php5 (php5-3745) | Nessus | SuSE Local Security Checks | high |
25678 | Debian DSA-1331-1 : php4 - several vulnerabilities | Nessus | Debian Local Security Checks | high |
25677 | Debian DSA-1330-1 : php5 - several vulnerabilities | Nessus | Debian Local Security Checks | critical |
25340 | GLSA-200705-19 : PHP: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
25334 | RHEL 5 : php (RHSA-2007:0348) | Nessus | Red Hat Local Security Checks | high |
25212 | Mandrake Linux Security Advisory : php (MDKSA-2007:102) | Nessus | Mandriva Local Security Checks | high |
25206 | CentOS 5 : php (CESA-2007:0348) | Nessus | CentOS Local Security Checks | high |
25193 | RHEL 4 : php (RHSA-2007:0349) | Nessus | Red Hat Local Security Checks | high |
25159 | PHP < 4.4.7 / 5.2.2 Multiple Vulnerabilities | Nessus | CGI abuses | high |