Mandriva Linux Security Advisory MDVSA-2014:115
http://www.mandriva.com/en/
______________________________
Package : php
Date : June 10, 2014
Affected: Business Server 1.0
______________________________
Problem Description:
Updated php packages fix security vulnerabilities:
A flaw was found in the way file's Composite Document Files (CDF)
format parser handle CDF files with many summary info entries.
The cdf_unpack_summary_info() function unnecessarily repeatedly read
the info from the same offset. This led to many file_printf() calls in
cdf_file_property_info(), which caused file to use an excessive amount
of CPU time when parsing a specially-crafted CDF file (CVE-2014-0237).
A flaw was found in the way file parsed property information from
Composite Document Files (CDF) files. A property entry with 0 elements
triggers an infinite loop (CVE-2014-0238).
PHP contains a bundled copy of the file utility's libmagic library,
so it was vulnerable to this issue. It has been updated to the 5.5.13
version, which fixes this issue and several other bugs.
Additionally, php-apc has been rebuilt against the updated php
packages.
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://advisories.mageia.org/
http://www.php.net/ChangeLog-
______________________________
Updated Packages:
Mandriva Business Server 1/X86_64:
8711779e81a50a4904aa865b48524e
5b6fa6fe481a7599d5c4e597c1d9bc
d7595fc5c03fcda523a6b55ab356a2
7d2e903f283e23fc24dc3a1ff4f748
e684cb737d10d699ac3ee8300158fb
0896588cd4d217382fe7edce11936b
14e6355367c688176676f53e62981d
19a4cc762f8b05ff9e0f9a489d6308
9f548d3786c32b85fff6bb51f25968
b8db5525d09f49a55b8e2b65d5de57
c17a7e419e090c6e87f6042e0a0d4d
e298564d779b0ec06b1ebfed4afa4e
2b3e212dd4dd34bc7c018e43f3d8b2
ee061099f739a00b9b614c9c368930
b212b1fecde3a01d3cf9e428e5b94c
eaec7f6df84daecc5e5f76b3d068b5
026b7278237e38d979f6cca904cede
8c3bab218b68f119e81e4b32a88a3c
bfba6c5ecb0ad7fca62d698e16bc59
ef0ad0dce52f6032ab818f8f116bb6
7fba1e0c6fd5966917a0ef29308320
9c5d684587774f46288190ebcb667a
3e50a38dc3647e63ca9f569043ddee
7160d5a371b1d10938896b3a349bbb
6cdbb890f3bd4e79f294b93e01f056
aadfb4c1e93043956ac535756deeb4
55c55ab806e72434bb51f440af6e67
6d8171c9e50dc93ffb96086888e18d
0ae0ae0fd51b352ded35e67d98945a
d2a501a6fe260527dfcf9b7a1a10bf
b289596cfbff32fa727d1a6f1e4f91
ff980b8a060fee4f0b7f5cdbc11864
970047da4f0e8520a00b5f2ae8e5a2
08cb4e6b70bb5d8c988b626c62d375
e1b13a6b4f448304d60568bdf390f7
756d526191c09b5c1163b648d29553
7ce3b6d6f5e05747c8dc29afd1dab4
19dfa9eaececdd180f6a0f07347932
8ca0d0b4b46cf1d37443a55b96e057
2471c8af7a847b3d13c8a519fa78ed
69b5a4852f380bd1f83f45021960fa
48b2a529902592be79fda68adf791b
f490ec2b03038f9dfb07c7baf80b96
9d3c2aadfc6b570c0e3a096214d44d
e996d335c93727f93f295dd5e7e62a
edb94ed0076da44690b2bae5763bdc
4baddbb93b3f3762e418fab8ba8bd9
b21e5a3f672f8cc7ca952d0a38660f
cd37ec13b2908d246ec96a22ad22fa
3683391016afb537b91b17113f8605
7d318534a12a7a8ffbdabd79775c82
4b631eb7e2c745751abfb58710e456
6a2ec65e4fad9af3cc8f8ba0f63a7a
883dc6088ec2f1c720b74327dffeef
ae0f47fb7c0f1e44b2ff5ec0fb3e8a
a5b4e4b42414a9e2cdb21df3536e9f
60f2ff75f09c0cd16fc6b6aad1742a
f8deb4a7555238285c37d4c6048095
bde8d1303001a649802d4d3c370af0
30854dc35b450154e23fbd1cd8ec48
a2c8af3e1a951d36eaebf1b58b7563
6f0530e3ea94463b826f77da51b659
7680c4d7bc14e8960954b23564a2a5
d63c45b031eac0d51cfe42d445d336
aa1c71889b8e6a95be194f402cd659
12f25f419fa8652c55c1a47bd64e18
9ca69fe4dc9d28f9651c2f2448bfde
7354023fdbe9c756fae68fb2649fac
59f0f3169959c31adb8333f1e597a7
35ff0c499c20239387daef7f60cec4
bec63d966cc6b9e756272baf668150
dc2e485d9587eb28a7b8b1915dd0f4
4c530928dfecb79e8de977555cb38f
cf24973b34d24e31942a1e04b63125
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą