Fedora 13 : maniadrive-1.2-23.fc13 / php-5.3.4-1.fc13.1 / php-eaccelerator- (2010-19011)

medium Nessus Plugin ID 51413
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.


The remote Fedora host is missing one or more security updates.


Security Enhancements and Fixes in PHP 5.3.4 :

- Fixed crash in zip extract method (possible CWE-170).

- Paths with NULL in them (foo\0bar.txt) are now considered as invalid (CVE-2006-7243).

- Fixed a possible double free in imap extension (Identified by Mateusz Kocielski). (CVE-2010-4150).

- Fixed NULL pointer dereference in ZipArchive::getArchiveComment. (CVE-2010-3709).

- Fixed possible flaw in open_basedir (CVE-2010-3436).

- Fixed MOPS-2010-24, fix string validation.

- Fixed symbolic resolution support when the target is a DFS share.

- Fixed bug #52929 (Segfault in filter_var with FILTER_VALIDATE_EMAIL with large amount of data) (CVE-2010-3710).

Key Bug Fixes in PHP 5.3.4 include :

- Added stat support for zip stream.

- Added follow_location (enabled by default) option for the http stream support.

- Added a 3rd parameter to get_html_translation_table.
It now takes a charset hint, like htmlentities et al.

- Implemented FR #52348, added new constant ZEND_MULTIBYTE to detect zend multibyte at runtime.

Full upstream Changelog : http://www.php.net/ChangeLog-5.php#5.3.4

This update also provides php-eaccelerator and maniadrive packages rebuild against update php.

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.


Update the affected maniadrive, php and / or php-eaccelerator packages.

See Also












Plugin Details

Severity: Medium

ID: 51413

File Name: fedora_2010-19011.nasl

Version: 1.14

Type: local

Agent: unix

Published: 1/5/2011

Updated: 1/11/2021

Dependencies: ssh_get_info.nasl

Risk Information


Risk Factor: Medium

Score: 6.7


Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: E:POC/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:maniadrive, p-cpe:/a:fedoraproject:fedora:php, p-cpe:/a:fedoraproject:fedora:php-eaccelerator, cpe:/o:fedoraproject:fedora:13

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/17/2010

Vulnerability Publication Date: 10/25/2010

Reference Information

CVE: CVE-2009-5016, CVE-2010-3709, CVE-2010-3710, CVE-2010-3870, CVE-2010-4150, CVE-2010-4156, CVE-2010-4409

BID: 43926, 44605, 44718, 44727, 44889, 44980, 45119

FEDORA: 2010-19011