FreeBSD : php -- multiple vulnerabilities (f5e52bf5-fc77-11db-8163-000e0c2e438a)

Medium Nessus Plugin ID 25207


The remote FreeBSD host is missing one or more security-related updates.


The PHP development team reports :

Security Enhancements and Fixes in PHP 5.2.2 and PHP 4.4.7 :

- Fixed CVE-2007-1001, GD wbmp used with invalid image size

- Fixed asciiz byte truncation inside mail()

- Fixed a bug in mb_parse_str() that can be used to activate register_globals

- Fixed unallocated memory access/double free in in array_user_key_compare()

- Fixed a double free inside session_regenerate_id()

- Added missing open_basedir & safe_mode checks to zip:// and bzip:// wrappers.

- Limit nesting level of input variables with max_input_nesting_level as fix for.

- Fixed CRLF injection inside ftp_putcmd().

- Fixed a possible super-global overwrite inside import_request_variables().

- Fixed a remotely trigger-able buffer overflow inside bundled libxmlrpc library.

Security Enhancements and Fixes in PHP 5.2.2 only :

- Fixed a header injection via Subject and To parameters to the mail() function

- Fixed wrong length calculation in unserialize S type.

- Fixed substr_compare and substr_count information leak.

- Fixed a remotely trigger-able buffer overflow inside make_http_soap_request().

- Fixed a buffer overflow inside user_filter_factory_create().

Security Enhancements and Fixes in PHP 4.4.7 only :

- XSS in phpinfo()


Update the affected packages.

See Also

Plugin Details

Severity: Medium

ID: 25207

File Name: freebsd_pkg_f5e52bf5fc7711db8163000e0c2e438a.nasl

Version: $Revision: 1.10 $

Type: local

Published: 2007/05/11

Modified: 2014/04/02

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:mod_php, p-cpe:/a:freebsd:freebsd:mod_php4, p-cpe:/a:freebsd:freebsd:mod_php4-twig, p-cpe:/a:freebsd:freebsd:mod_php5, p-cpe:/a:freebsd:freebsd:php4, p-cpe:/a:freebsd:freebsd:php4-cgi, p-cpe:/a:freebsd:freebsd:php4-cli, p-cpe:/a:freebsd:freebsd:php4-dtc, p-cpe:/a:freebsd:freebsd:php4-horde, p-cpe:/a:freebsd:freebsd:php4-nms, p-cpe:/a:freebsd:freebsd:php4-odbc, p-cpe:/a:freebsd:freebsd:php4-session, p-cpe:/a:freebsd:freebsd:php4-shmop, p-cpe:/a:freebsd:freebsd:php4-wddx, p-cpe:/a:freebsd:freebsd:php5, p-cpe:/a:freebsd:freebsd:php5-cgi, p-cpe:/a:freebsd:freebsd:php5-cli, p-cpe:/a:freebsd:freebsd:php5-dtc, p-cpe:/a:freebsd:freebsd:php5-horde, p-cpe:/a:freebsd:freebsd:php5-imap, p-cpe:/a:freebsd:freebsd:php5-nms, p-cpe:/a:freebsd:freebsd:php5-odbc, p-cpe:/a:freebsd:freebsd:php5-session, p-cpe:/a:freebsd:freebsd:php5-shmop, p-cpe:/a:freebsd:freebsd:php5-sqlite, p-cpe:/a:freebsd:freebsd:php5-wddx, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2007/05/07

Vulnerability Publication Date: 2007/05/03

Reference Information

CVE: CVE-2007-1001