Fedora 13 : maniadrive-1.2-23.fc13 / php-5.3.4-1.fc13.1 / php-eaccelerator- (2010-19011)

Medium Nessus Plugin ID 51413


The remote Fedora host is missing one or more security updates.


Security Enhancements and Fixes in PHP 5.3.4 :

- Fixed crash in zip extract method (possible CWE-170).

- Paths with NULL in them (foo\0bar.txt) are now considered as invalid (CVE-2006-7243).

- Fixed a possible double free in imap extension (Identified by Mateusz Kocielski). (CVE-2010-4150).

- Fixed NULL pointer dereference in ZipArchive::getArchiveComment. (CVE-2010-3709).

- Fixed possible flaw in open_basedir (CVE-2010-3436).

- Fixed MOPS-2010-24, fix string validation.

- Fixed symbolic resolution support when the target is a DFS share.

- Fixed bug #52929 (Segfault in filter_var with FILTER_VALIDATE_EMAIL with large amount of data) (CVE-2010-3710).

Key Bug Fixes in PHP 5.3.4 include :

- Added stat support for zip stream.

- Added follow_location (enabled by default) option for the http stream support.

- Added a 3rd parameter to get_html_translation_table.
It now takes a charset hint, like htmlentities et al.

- Implemented FR #52348, added new constant ZEND_MULTIBYTE to detect zend multibyte at runtime.

Full upstream Changelog : http://www.php.net/ChangeLog-5.php#5.3.4

This update also provides php-eaccelerator and maniadrive packages rebuild against update php.

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.


Update the affected maniadrive, php and / or php-eaccelerator packages.

See Also












Plugin Details

Severity: Medium

ID: 51413

File Name: fedora_2010-19011.nasl

Version: $Revision: 1.10 $

Type: local

Agent: unix

Published: 2011/01/05

Modified: 2016/05/11

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:maniadrive, p-cpe:/a:fedoraproject:fedora:php, p-cpe:/a:fedoraproject:fedora:php-eaccelerator, cpe:/o:fedoraproject:fedora:13

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2010/12/17

Reference Information

CVE: CVE-2009-5016, CVE-2010-3709, CVE-2010-3710, CVE-2010-3870, CVE-2010-4150, CVE-2010-4156, CVE-2010-4409

BID: 43926, 44605, 44718, 44727, 44889, 44980, 45119

OSVDB: 66086, 68597, 69099, 69109, 69110, 69227, 69230, 69651, 69660

FEDORA: 2010-19011