SuSE 10 Security Update : PHP5 (ZYPP Patch Number 7221)
Medium Nessus Plugin ID 50975
SynopsisThe remote SuSE 10 host is missing a security-related patch.
DescriptionThe following issues have been fixed :
- Insufficient handling of certain character sequences in the utf8_decode() function could be leveraged to conduct cross-site scripting (XSS) attacks. (CVE-2010-3870)
- php5 could also consume large amounts of memory and crash if a long mail address was passed to filter_var() with the parameter FILTER_VALIDATE_EMAIL.
SolutionApply ZYPP patch number 7221.