Executive Summary
| Summary | |
|---|---|
| Title | PHP vulnerabilities |
| Informations | |||
|---|---|---|---|
| Name | USN-882-1 | First vendor Publication | 2010-01-13 |
| Vendor | Ubuntu | Last vendor Modification | 2010-01-13 |
| Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 10 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 Ubuntu 9.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: php5-cgi 5.1.2-1ubuntu3.18 php5-cli 5.1.2-1ubuntu3.18 Ubuntu 8.04 LTS: php5-cgi 5.2.4-2ubuntu5.10 php5-cli 5.2.4-2ubuntu5.10 Ubuntu 8.10: php5-cgi 5.2.6-2ubuntu4.6 php5-cli 5.2.6-2ubuntu4.6 Ubuntu 9.04: php5-cgi 5.2.6.dfsg.1-3ubuntu4.5 php5-cli 5.2.6.dfsg.1-3ubuntu4.5 Ubuntu 9.10: php5-cgi 5.2.10.dfsg.1-2ubuntu6.4 php5-cli 5.2.10.dfsg.1-2ubuntu6.4 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Maksymilian Arciemowicz discovered that PHP did not properly handle the ini_restore function. An attacker could exploit this issue to obtain random memory contents or to cause the PHP server to crash, resulting in a denial of service. (CVE-2009-2626) It was discovered that the htmlspecialchars function did not properly handle certain character sequences, which could result in browsers becoming vulnerable to cross-site scripting attacks when processing the output. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data (such as passwords), within the same domain. (CVE-2009-4142) Stefan Esser discovered that PHP did not properly handle session data. An attacker could exploit this issue to bypass safe_mode or open_basedir restrictions. (CVE-2009-4143) |
Original Source
| Url : http://www.ubuntu.com/usn/USN-882-1 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:7085 | |||
| Oval ID: | oval:org.mitre.oval:def:7085 | ||
| Title: | HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS) | ||
| Description: | The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-4142 |
Version: | 3 |
| Platform(s): | HP-UX 11 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:7439 | |||
| Oval ID: | oval:org.mitre.oval:def:7439 | ||
| Title: | HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS) | ||
| Description: | PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-4143 |
Version: | 3 |
| Platform(s): | HP-UX 11 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 61209 | PHP htmlspecialchars() Invalid Byte Sequence XSS |
| 61208 | PHP $_SESSION Interrupt Corruption Unspecified Issue |
| 60654 | PHP zend_ini.c zend_restore_ini_entry_cb Function Memory Content Information ... |

USN-882-1
(Critical)
(Medium)






