Paketname
php-pear
Datum
2005-08-22
Advisory ID
MDKSA-2005:146
Betroffene Versionen
10.2 x86_64 , 10.0 amd64 , 10.2 i586 , 10.1 i586 , 10.0 i586 , CS3.0 x86_64 , CS3.0 i586 , 10.1 x86_64

Problembeschreibung

A problem was discovered in the PEAR XML-RPC Server package included in the php-pear package. If a PHP script which implements the XML-RPC Server is used, it would be possible for a remote attacker to construct an XML-RPC request which would cause PHP to execute arbitrary commands as the 'apache' user.

Aktualisierte Pakete

10.2 x86_64

 484af9862c08f5fdec98007d74fdcf8c  x86_64/10.2/RPMS/php-pear-4.3.10-3.2.102mdk.noarch.rpm
28e358ce40a0561251ba34d909a7c617  x86_64/10.2/SRPMS/php-pear-4.3.10-3.2.102mdk.src.rpm

10.0 amd64

 ad5790382b19a06f31d341d7eba05fb6  amd64/10.0/RPMS/php-pear-4.3.4-3.2.100mdk.noarch.rpm
7d41047a2fb997725773ae9dccd76ff9  amd64/10.0/SRPMS/php-pear-4.3.4-3.2.100mdk.src.rpm

10.2 i586

 484af9862c08f5fdec98007d74fdcf8c  10.2/RPMS/php-pear-4.3.10-3.2.102mdk.noarch.rpm
28e358ce40a0561251ba34d909a7c617  10.2/SRPMS/php-pear-4.3.10-3.2.102mdk.src.rpm

10.1 i586

 3c0b4ed15139d42df9be6ed177a571d6  10.1/RPMS/php-pear-4.3.8-1.2.101mdk.noarch.rpm
ffd4b96fe8e05b7246eccd881563229d  10.1/SRPMS/php-pear-4.3.8-1.2.101mdk.src.rpm

10.0 i586

 ad5790382b19a06f31d341d7eba05fb6  10.0/RPMS/php-pear-4.3.4-3.2.100mdk.noarch.rpm
7d41047a2fb997725773ae9dccd76ff9  10.0/SRPMS/php-pear-4.3.4-3.2.100mdk.src.rpm

CS3.0 x86_64

 4f1eede09f0e47209b13e7c8168bcb79  x86_64/corporate/3.0/RPMS/php-pear-4.3.4-3.2.C30mdk.noarch.rpm
e5e1fa37415a8761c2b25799ef8fffb5  x86_64/corporate/3.0/SRPMS/php-pear-4.3.4-3.2.C30mdk.src.rpm

CS3.0 i586

 4f1eede09f0e47209b13e7c8168bcb79  corporate/3.0/RPMS/php-pear-4.3.4-3.2.C30mdk.noarch.rpm
e5e1fa37415a8761c2b25799ef8fffb5  corporate/3.0/SRPMS/php-pear-4.3.4-3.2.C30mdk.src.rpm

10.1 x86_64

 3c0b4ed15139d42df9be6ed177a571d6  x86_64/10.1/RPMS/php-pear-4.3.8-1.2.101mdk.noarch.rpm
ffd4b96fe8e05b7246eccd881563229d  x86_64/10.1/SRPMS/php-pear-4.3.8-1.2.101mdk.src.rpm

Referenzen