Description: rPath has issued an update for php, php-mysql and php-pgsql. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions or by malicious people to potentially compromise a vulnerable system.
Solution: Update to:
"php=conary.rpath.com@rpl:1/4.3.11-15.16-1"
"php-mysql=conary.rpath.com@rpl:1/4.3.11-15.16-1"
"php-pgsql=conary.rpath.com@rpl:1/4.3.11-15.16-1"
Changelog: 2007-12-12: Updated "Solution" section due to an unnecessary and incorrect patch for CVE-2007-4659. Updated CVE references and added link to updated rPath advisory.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.