Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2001.054 -- RHSA-2000:136-10 Updated PHP packages available for Red Hat Linux 5.2, 6.x, and 7 8 February 2001 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: PHP Vendor: Red Hat Operating System: Red Hat Linux 5.2 Red Hat Linux 6.0 Red Hat Linux 6.1 Red Hat Linux 6.2 Red Hat Linux 7.0 Impact: Denial of Service Access Required: Remote - --------------------------BEGIN INCLUDED TEXT-------------------- - --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated PHP packages available for Red Hat Linux 5.2, 6.x, and 7 Advisory ID: RHSA-2000:136-10 Issue date: 2000-12-20 Updated on: 2001-01-24 Product: Red Hat Linux Keywords: php multipart gd engine Cross references: RHSA-2000:88 RHBA-2000:112 Obsoletes: - --------------------------------------------------------------------- 1. Topic: Updated PHP packages are now available for Red Hat Linux 5.2, 6.x, and 7. 2. Relevant releases/architectures: Red Hat Linux 5.2 - alpha, i386, sparc Red Hat Linux 6.0 - i386, sparc Red Hat Linux 6.1 - alpha, i386, sparc Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 3. Problem description: Clients uploading "multipart/form-data" information with form requests could cause PHP 3.0.17 to crash. The GD module was not compiled into the previously-issued PHP 4.0.3pl1 errata packages. The php-mysql package is linked against an older version of the libmysqlclient shared library, which was obsoleted by a previous MySQL errata. Security holes in versions 4.0.0 through 4.0.4 of the PHP Apache module have been found. 4. Solution: Because of dependencies, the packages must be installed as a group. After downloading all RPMs needed for your particular architecture, run: rpm -Fvh php* Then restart your web server: /etc/rc.d/init.d/httpd restart 5. Bug IDs fixed (http://bugzilla.redhat.com/bugzilla for more info): 19906 - PHP 3.0.17-1.6.2 crashes apache reproducable 21291 - php should be rebuild on new environment 21620 - configure option --enable-wddx not used 21664 - updated redhat 7 PHP rpm's broken 22376 - php-4.0.3pl1 from 7.0 errata fails to install gd.so ld 23690 - php-mysql needs rebuild in light of mysql-3.23.29-1 23902 - PHP4.0.4pl1 solve 2 security problems 6. RPMs required: Red Hat Linux 5.2: SRPMS: ftp://updates.redhat.com/5.2/SRPMS/php-3.0.18-1.5.x.src.rpm alpha: ftp://updates.redhat.com/5.2/alpha/php-3.0.18-1.5.x.alpha.rpm ftp://updates.redhat.com/5.2/alpha/php-manual-3.0.18-1.5.x.alpha.rpm ftp://updates.redhat.com/5.2/alpha/php-pgsql-3.0.18-1.5.x.alpha.rpm i386: ftp://updates.redhat.com/5.2/i386/php-3.0.18-1.5.x.i386.rpm ftp://updates.redhat.com/5.2/i386/php-manual-3.0.18-1.5.x.i386.rpm ftp://updates.redhat.com/5.2/i386/php-pgsql-3.0.18-1.5.x.i386.rpm sparc: ftp://updates.redhat.com/5.2/sparc/php-3.0.18-1.5.x.sparc.rpm ftp://updates.redhat.com/5.2/sparc/php-manual-3.0.18-1.5.x.sparc.rpm ftp://updates.redhat.com/5.2/sparc/php-pgsql-3.0.18-1.5.x.sparc.rpm Red Hat Linux 6.0: SRPMS: ftp://updates.redhat.com/6.0/SRPMS/php-3.0.18-1.6.x.src.rpm i386: ftp://updates.redhat.com/6.0/i386/php-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.0/i386/php-imap-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.0/i386/php-ldap-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.0/i386/php-manual-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.0/i386/php-pgsql-3.0.18-1.6.x.i386.rpm sparc: ftp://updates.redhat.com/6.0/sparc/php-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.0/sparc/php-imap-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.0/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.0/sparc/php-manual-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.0/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm Red Hat Linux 6.1: SRPMS: ftp://updates.redhat.com/6.1/SRPMS/php-3.0.18-1.6.x.src.rpm alpha: ftp://updates.redhat.com/6.1/alpha/php-3.0.18-1.6.x.alpha.rpm ftp://updates.redhat.com/6.1/alpha/php-imap-3.0.18-1.6.x.alpha.rpm ftp://updates.redhat.com/6.1/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm ftp://updates.redhat.com/6.1/alpha/php-manual-3.0.18-1.6.x.alpha.rpm ftp://updates.redhat.com/6.1/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm i386: ftp://updates.redhat.com/6.1/i386/php-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.1/i386/php-imap-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.1/i386/php-ldap-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.1/i386/php-manual-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.1/i386/php-pgsql-3.0.18-1.6.x.i386.rpm sparc: ftp://updates.redhat.com/6.1/sparc/php-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.1/sparc/php-imap-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.1/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.1/sparc/php-manual-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.1/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm Red Hat Linux 6.2: SRPMS: ftp://updates.redhat.com/6.2/SRPMS/php-3.0.18-1.6.x.src.rpm alpha: ftp://updates.redhat.com/6.2/alpha/php-3.0.18-1.6.x.alpha.rpm ftp://updates.redhat.com/6.2/alpha/php-imap-3.0.18-1.6.x.alpha.rpm ftp://updates.redhat.com/6.2/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm ftp://updates.redhat.com/6.2/alpha/php-manual-3.0.18-1.6.x.alpha.rpm ftp://updates.redhat.com/6.2/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm i386: ftp://updates.redhat.com/6.2/i386/php-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.2/i386/php-imap-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.2/i386/php-ldap-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.2/i386/php-manual-3.0.18-1.6.x.i386.rpm ftp://updates.redhat.com/6.2/i386/php-pgsql-3.0.18-1.6.x.i386.rpm sparc: ftp://updates.redhat.com/6.2/sparc/php-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.2/sparc/php-imap-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.2/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.2/sparc/php-manual-3.0.18-1.6.x.sparc.rpm ftp://updates.redhat.com/6.2/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm Red Hat Linux 7.0: SRPMS: ftp://updates.redhat.com/7.0/SRPMS/php-4.0.4pl1-3.src.rpm alpha: ftp://updates.redhat.com/7.0/alpha/php-4.0.4pl1-3.alpha.rpm ftp://updates.redhat.com/7.0/alpha/php-imap-4.0.4pl1-3.alpha.rpm ftp://updates.redhat.com/7.0/alpha/php-ldap-4.0.4pl1-3.alpha.rpm ftp://updates.redhat.com/7.0/alpha/php-manual-4.0.4pl1-3.alpha.rpm ftp://updates.redhat.com/7.0/alpha/php-mysql-4.0.4pl1-3.alpha.rpm ftp://updates.redhat.com/7.0/alpha/php-pgsql-4.0.4pl1-3.alpha.rpm i386: ftp://updates.redhat.com/7.0/i386/php-4.0.4pl1-3.i386.rpm ftp://updates.redhat.com/7.0/i386/php-imap-4.0.4pl1-3.i386.rpm ftp://updates.redhat.com/7.0/i386/php-ldap-4.0.4pl1-3.i386.rpm ftp://updates.redhat.com/7.0/i386/php-manual-4.0.4pl1-3.i386.rpm ftp://updates.redhat.com/7.0/i386/php-mysql-4.0.4pl1-3.i386.rpm ftp://updates.redhat.com/7.0/i386/php-pgsql-4.0.4pl1-3.i386.rpm 7. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- fd62a3d0460fb6442d01f661e95275ab 5.2/SRPMS/php-3.0.18-1.5.x.src.rpm 625d416b98954143c0736dfd2143831b 5.2/alpha/php-3.0.18-1.5.x.alpha.rpm 5434b59b75a0227068b15175dbae3e1c 5.2/alpha/php-manual-3.0.18-1.5.x.alpha.rpm 6ee3385d9e4e7e0308e14d437bf197a9 5.2/alpha/php-pgsql-3.0.18-1.5.x.alpha.rpm c9c2f6e2202519c204886cb01bbc5170 5.2/i386/php-3.0.18-1.5.x.i386.rpm e2047b5a28cc6ec9c987a7c168d57bab 5.2/i386/php-manual-3.0.18-1.5.x.i386.rpm 3880561630fbb66dcc8432601010904d 5.2/i386/php-pgsql-3.0.18-1.5.x.i386.rpm 913fcfeec79c5c9ee57d76c519f8e652 5.2/sparc/php-3.0.18-1.5.x.sparc.rpm 27f4790a441e0661322a54082e067699 5.2/sparc/php-manual-3.0.18-1.5.x.sparc.rpm a81d8e856451349c7b9b9b0597aa97ad 5.2/sparc/php-pgsql-3.0.18-1.5.x.sparc.rpm f135fa49dee86cb2fd9aba665cda64d1 6.0/SRPMS/php-3.0.18-1.6.x.src.rpm 13998f321e1787af7bac4f01e9e01b81 6.0/i386/php-3.0.18-1.6.x.i386.rpm d7a6f3e9d64c1edbeb10a1170e0d90b2 6.0/i386/php-imap-3.0.18-1.6.x.i386.rpm bd3d6c413faf3ca0e271c7195fe5c2b1 6.0/i386/php-ldap-3.0.18-1.6.x.i386.rpm 9e19cc6e58fbeff7095abcd02120174f 6.0/i386/php-manual-3.0.18-1.6.x.i386.rpm adf510253a012e01d0cc1bb631fd423f 6.0/i386/php-pgsql-3.0.18-1.6.x.i386.rpm 9f54bf780fbef67a03d7065a6d69f762 6.0/sparc/php-3.0.18-1.6.x.sparc.rpm d17460149d0375a991773bf6f296957a 6.0/sparc/php-imap-3.0.18-1.6.x.sparc.rpm d4c00495db0fbb0014697afc25cc3eca 6.0/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm 9ffb47a272984fd2757e09747e859695 6.0/sparc/php-manual-3.0.18-1.6.x.sparc.rpm 09acd6bbd4c19a57c0bbf64fcd64f2b8 6.0/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm f135fa49dee86cb2fd9aba665cda64d1 6.1/SRPMS/php-3.0.18-1.6.x.src.rpm ce0b8c6d8be5db195b70c3631e75e200 6.1/alpha/php-3.0.18-1.6.x.alpha.rpm 42e64510ed0fcce493cc20181eafd419 6.1/alpha/php-imap-3.0.18-1.6.x.alpha.rpm 53ac23e30083ae09d3a0aee04039e666 6.1/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm 39491a3833a9bd926b81fdc500e9a39f 6.1/alpha/php-manual-3.0.18-1.6.x.alpha.rpm 85aeccf83a08e9d69c5464c17fc9c445 6.1/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm 13998f321e1787af7bac4f01e9e01b81 6.1/i386/php-3.0.18-1.6.x.i386.rpm d7a6f3e9d64c1edbeb10a1170e0d90b2 6.1/i386/php-imap-3.0.18-1.6.x.i386.rpm bd3d6c413faf3ca0e271c7195fe5c2b1 6.1/i386/php-ldap-3.0.18-1.6.x.i386.rpm 9e19cc6e58fbeff7095abcd02120174f 6.1/i386/php-manual-3.0.18-1.6.x.i386.rpm adf510253a012e01d0cc1bb631fd423f 6.1/i386/php-pgsql-3.0.18-1.6.x.i386.rpm 9f54bf780fbef67a03d7065a6d69f762 6.1/sparc/php-3.0.18-1.6.x.sparc.rpm d17460149d0375a991773bf6f296957a 6.1/sparc/php-imap-3.0.18-1.6.x.sparc.rpm d4c00495db0fbb0014697afc25cc3eca 6.1/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm 9ffb47a272984fd2757e09747e859695 6.1/sparc/php-manual-3.0.18-1.6.x.sparc.rpm 09acd6bbd4c19a57c0bbf64fcd64f2b8 6.1/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm f135fa49dee86cb2fd9aba665cda64d1 6.2/SRPMS/php-3.0.18-1.6.x.src.rpm ce0b8c6d8be5db195b70c3631e75e200 6.2/alpha/php-3.0.18-1.6.x.alpha.rpm 42e64510ed0fcce493cc20181eafd419 6.2/alpha/php-imap-3.0.18-1.6.x.alpha.rpm 53ac23e30083ae09d3a0aee04039e666 6.2/alpha/php-ldap-3.0.18-1.6.x.alpha.rpm 39491a3833a9bd926b81fdc500e9a39f 6.2/alpha/php-manual-3.0.18-1.6.x.alpha.rpm 85aeccf83a08e9d69c5464c17fc9c445 6.2/alpha/php-pgsql-3.0.18-1.6.x.alpha.rpm 13998f321e1787af7bac4f01e9e01b81 6.2/i386/php-3.0.18-1.6.x.i386.rpm d7a6f3e9d64c1edbeb10a1170e0d90b2 6.2/i386/php-imap-3.0.18-1.6.x.i386.rpm bd3d6c413faf3ca0e271c7195fe5c2b1 6.2/i386/php-ldap-3.0.18-1.6.x.i386.rpm 9e19cc6e58fbeff7095abcd02120174f 6.2/i386/php-manual-3.0.18-1.6.x.i386.rpm adf510253a012e01d0cc1bb631fd423f 6.2/i386/php-pgsql-3.0.18-1.6.x.i386.rpm 9f54bf780fbef67a03d7065a6d69f762 6.2/sparc/php-3.0.18-1.6.x.sparc.rpm d17460149d0375a991773bf6f296957a 6.2/sparc/php-imap-3.0.18-1.6.x.sparc.rpm d4c00495db0fbb0014697afc25cc3eca 6.2/sparc/php-ldap-3.0.18-1.6.x.sparc.rpm 9ffb47a272984fd2757e09747e859695 6.2/sparc/php-manual-3.0.18-1.6.x.sparc.rpm 09acd6bbd4c19a57c0bbf64fcd64f2b8 6.2/sparc/php-pgsql-3.0.18-1.6.x.sparc.rpm fc2f89fb24cdcae8485a334f2e0f2372 7.0/SRPMS/php-4.0.4pl1-3.src.rpm 4f7b7d6c57c3d58595b394a6b69b0830 7.0/alpha/php-4.0.4pl1-3.alpha.rpm bc11c5346d930ac12236856b8c64f33c 7.0/alpha/php-imap-4.0.4pl1-3.alpha.rpm 8d98cdcf391c251d96685d5dce7fe588 7.0/alpha/php-ldap-4.0.4pl1-3.alpha.rpm 92ad775f67ff1d74fae764aa592e1103 7.0/alpha/php-manual-4.0.4pl1-3.alpha.rpm 26b438a4f276cbdec1a22591214f4ad6 7.0/alpha/php-mysql-4.0.4pl1-3.alpha.rpm ef1cd2ed0bf74a2dd491fe34c686f8b5 7.0/alpha/php-pgsql-4.0.4pl1-3.alpha.rpm 2946e063efcb2be68f789624168b1a8b 7.0/i386/php-4.0.4pl1-3.i386.rpm fdb049b4572bff635b5327cdbfae1266 7.0/i386/php-imap-4.0.4pl1-3.i386.rpm 4408734b5dd1c60d325d95216999f938 7.0/i386/php-ldap-4.0.4pl1-3.i386.rpm 502a66f4e11d98cd3f266bd1f897f9d7 7.0/i386/php-manual-4.0.4pl1-3.i386.rpm 066bcf976c3f930d16f191813473218c 7.0/i386/php-mysql-4.0.4pl1-3.i386.rpm 1660362c37dd4b603aa733f2d92c2e94 7.0/i386/php-pgsql-4.0.4pl1-3.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: http://www.redhat.com/corp/contact.html You can verify each package with the following command: rpm --checksig <filename> If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg <filename> 8. References: http://www.securityfocus.com/bid/2205 http://bugs.php.net/bugs-php3.php?id=7719 Copyright(c) 2000, 2001 Red Hat, Inc. - --------------------------END INCLUDED TEXT-------------------- This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to use any or all of this information is the responsibility of each user or organisation, and should be done so in accordance with site policies and procedures. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the original authors to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/Information/advisories.html If you believe that your system has been compromised, contact AusCERT or your representative in FIRST (Forum of Incident Response and Security Teams). Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for emergencies. -----BEGIN PGP SIGNATURE----- Version: 2.6.3i Charset: noconv Comment: ftp://ftp.auscert.org.au/pub/auscert/AUSCERT_PGP.key iQCVAwUBOoLO3yh9+71yA2DNAQHaFAQAnDCpVUohqlmMS1hkUeiZzPOjIwiToj9N m0Yden09QzV7fugLeR3FC0FWry7lwR5ZCNx0BhWg+As7CruwXTORtnTsvlgXnWiS UOcVy+fMD15yhCUGpu3yYLE3EH6iJV1DiMXy1IjLKNDUB9WSouIT0XvlsA9eCqsS dC/ElygjC1I= =t2AS -----END PGP SIGNATURE-----