Description: rPath has issued an update for php, php-mysql and php-pgsql. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions or by malicious people to potentially compromise a vulnerable system.
Solution: Update to:
"php=conary.rpath.com@rpl:1/4.3.11-15.16-1"
"php-mysql=conary.rpath.com@rpl:1/4.3.11-15.16-1"
"php-pgsql=conary.rpath.com@rpl:1/4.3.11-15.16-1"
Changelog: 2007-12-12: Updated "Solution" section due to an unnecessary and incorrect patch for CVE-2007-4659. Updated CVE references and added link to updated rPath advisory.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.