Lucene search

K
ubuntuUbuntuUSN-99-2
HistoryMar 24, 2005 - 12:00 a.m.

Fixed php4 packages for USN-99-1

2005-03-2400:00:00
ubuntu.com
49

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.007

Percentile

80.2%

Releases

  • Ubuntu 4.10

Details

USN-99-1 fixed a safe mode bypass which allowed malicious PHP scripts
to circumvent path restrictions by creating a specially crafted
directory whose length exceeded the capacity of the realpath()
function (CAN-2004-1064). However, this caused severe regressions,
some applications like SquirrelMail and Gallery did not work any
more, and the package ‘php4-pear’ was empty. The current version
repairs this.

In addition this update fixes a crash of the PHP interpreter if
curl_init() was called with a non-string argument. Please note that
this is not security relevant since this condition usually cannot be
triggered externally.

OSVersionArchitecturePackageVersionFilename
Ubuntu4.10noarchlibapache2-mod-php4< *UNKNOWN
Ubuntu4.10noarchphp4-cgi< *UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.007

Percentile

80.2%