Author: stef-guest Date: 2007-04-30 21:42:25 +0000 (Mon, 30 Apr 2007) New Revision: 5753 Modified: data/CVE/list Log: record more php4 and php5 fixes Modified: data/CVE/list ==================================================================--- data/CVE/list 2007-04-30 18:52:31 UTC (rev 5752) +++ data/CVE/list 2007-04-30 21:42:25 UTC (rev 5753) @@ -917,7 +917,7 @@ RESERVED CVE-2007-1900 (CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ...) {DSA-1283-1} - - php5 <unfixed> (low) + - php5 5.2.0-11 (low) CVE-2007-1899 RESERVED CVE-2007-1898 @@ -942,7 +942,7 @@ NOTE: local code execution only, possibly only on FreeBSD CVE-2007-1889 (Integer signedness error in the _zend_mm_alloc_int function in the ...) {DSA-1283-1} - - php5 <unfixed> (medium) + - php5 5.2.0-11 (medium) CVE-2007-1888 (Buffer overflow in the sqlite_decode_binary function in src/encode.c ...) - sqlite <unfixed> (medium) NOTE: this is really just an "unsafe" API, not really a security issue against sqlite itself. @@ -950,7 +950,7 @@ CVE-2007-1887 (Buffer overflow in the sqlite_decode_binary function in the bundled ...) {DSA-1283-1} - php4 <not-affected> (SQLite not enabled in PHP 4 packages) - - php5 <unfixed> (medium) + - php5 5.2.0-11 (medium) NOTE: php5 is vulnerable due to improper use of the system sqlite libs CVE-2007-1886 (Integer overflow in the str_replace function in PHP 4.4.5 and PHP ...) NOT-FOR-US: Duplicate of CVE-2007-1885 @@ -1091,7 +1091,7 @@ NOTE: Dupe of CVE-2007-0906; Fixed in DSA-1264, php5 5.2.0-9, php4 6:4.4.4-9 CVE-2007-1824 (Buffer overflow in the php_stream_filter_create function in PHP 5 ...) {DSA-1283-1} - - php5 <unfixed> (medium) + - php5 5.2.0-11 (medium) CVE-2007-1823 (T-Mobile voice mail systems allow remote attackers to retrieve or ...) NOT-FOR-US: T-Mobile CVE-2007-1822 (Alcatel-Lucent Lucent Technologies voice mail systems allow remote ...) @@ -1215,7 +1215,7 @@ NOT-FOR-US: Eve-Nuke CVE-2007-1777 (Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 ...) {DSA-1283-1 DSA-1282-1} - - php4 <unfixed> (medium) + - php4 6:4.4.6-1 (medium) CVE-2007-1776 (SQL injection vulnerability in index.php in the DesignForJoomla.com ...) NOT-FOR-US: D4J eZine CVE-2007-1775 (Unrestricted file upload vulnerability in upload.php3 in JBrowser 2.4 ...) @@ -1337,7 +1337,7 @@ {DSA-1283-1 DSA-1282-1} - php4 <unfixed> (medium) [sarge] - php4 <not-affected> (Vulnerable code not present) - - php5 <unfixed> (medium) + - php5 5.2.0-11 (medium) CVE-2007-1717 (The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 ...) - php4 <unfixed> (unimportant) - php5 <unfixed> (unimportant) @@ -1653,7 +1653,7 @@ NOTE: Dupe of CVE-2007-0907; Fixed in DSA-1264, php5 5.2.0-9, php4 6:4.4.4-9 CVE-2007-1583 (The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through ...) {DSA-1283-1} - - php5 <unfixed> (medium) + - php5 5.2.0-11 (medium) - php4 <unfixed> (medium) CVE-2007-1582 (The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 ...) - php5 <unfixed> (unimportant) @@ -1794,7 +1794,7 @@ - php5 <unfixed> (medium) CVE-2007-1521 (Double free vulnerability in PHP 5.2.1 and earlier allows ...) {DSA-1283-1 DSA-1282-1} - - php5 <unfixed> (medium) + - php5 5.2.0-11 (medium) - php4 <unfixed> (medium) CVE-2007-1520 (The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 does ...) NOT-FOR-US: PHP-Nuke @@ -1954,10 +1954,10 @@ NOT-FOR-US: Fantastico CVE-2007-1454 (ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the ...) {DSA-1283-1} - - php5 <unfixed> (medium) + - php5 5.2.0-11 (medium) CVE-2007-1453 (Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering ...) {DSA-1283-1} - - php5 <unfixed> (medium) + - php5 5.2.0-11 (medium) CVE-2007-1452 (The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement ...) - php5 <unfixed> (low) CVE-2007-1451 (GuppY 4.0 allows remote attackers to delete arbitrary files via a ...) @@ -2142,8 +2142,8 @@ CVE-2007-1380 (The php_binary serialization handler in the session extension in PHP ...) {DSA-1283-1 DSA-1282-1} [etch] - php5 5.2.0-8+etch1 - - php4 <unfixed> (low) - - php5 <unfixed> (low) + - php4 6:4.4.6-1 (low) + - php5 5.2.0-11 (low) CVE-2007-1379 (The ovrimos_close function in the Ovrimos extension for PHP before ...) - php4 <not-affected> (Ovrimus support not included in Debian''s PHP packages) CVE-2007-1378 (The ovrimos_longreadlen function in the Ovrimos extension for PHP ...) @@ -2153,11 +2153,11 @@ CVE-2007-1376 (The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x ...) {DSA-1283-1} - php4 <unfixed> (unimportant) - - php5 <unfixed> (unimportant) + - php5 5.2.0-11 (unimportant) NOTE: Only triggerable by malicious script CVE-2007-1375 (Integer overflow in the substr_compare function in PHP 5.2.1 and ...) {DSA-1283-1} - - php5 <unfixed> (low) + - php5 5.2.0-11 (low) NOTE: Should be fixed, could be used as a stepstone for further attacks CVE-2007-1374 (Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz ...) NOT-FOR-US: Snitz Forums @@ -2408,7 +2408,7 @@ NOTE: Non-issue, explicit debug feature CVE-2007-1286 (Integer overflow in PHP 4.4.4 and earlier allows remote ...) {DSA-1283-1 DSA-1282-1} - - php4 <unfixed> (low) + - php4 6:4.4.6-1 (low) CVE-2007-1285 (The Zend Engine in PHP 4.x and 5.x allows remote attackers to cause a ...) - php5 <unfixed> (unimportant) - php4 <unfixed> (unimportant)