Executive Summary
Summary | |
---|---|
Title | php5 regression update |
Informations | |||
---|---|---|---|
Name | DSA-3008 | First vendor Publication | 2014-08-21 |
Vendor | Debian | Last vendor Modification | 2014-08-21 |
Severity (Vendor) | N/A | Revision | 2 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
This update corrects a packaging error for the packages released in DSA-3008-1. The new sessionclean script used in the updated cronjob in /etc/cron.d/php5 was not installed into the php5-common package. No other changes are introduced. For reference, the original advisory text follows. Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2014-3538 It was discovered that the original fix for CVE-2013-7345 did not sufficiently address the problem. A remote attacker could still cause a denial of service (CPU consumption) via a specially-crafted input file that triggers backtracking during processing of an awk regular expression rule. CVE-2014-3587 It was discovered that the CDF parser of the fileinfo module does not properly process malformed files in the Composite Document File (CDF) format, leading to crashes. CVE-2014-3597 It was discovered that the original fix for CVE-2014-4049 did not completely address the issue. A malicious server or man-in-the-middle attacker could cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record. CVE-2014-4670 It was discovered that PHP incorrectly handled certain SPL Iterators. A local attacker could use this flaw to cause PHP to crash, resulting in a denial of service. For the stable distribution (wheezy), these problems have been fixed in version 5.4.4-14+deb7u13. In addition, this update contains several bugfixes originally targeted for the upcoming Wheezy point release. For the unstable distribution (sid), these problems will be fied soon. We recommend that you upgrade your php5 packages. |
Original Source
Url : http://www.debian.org/security/2014/dsa-3008 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
50 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
25 % | CWE-399 | Resource Management Errors |
25 % | CWE-189 | Numeric Errors (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:23708 | |||
Oval ID: | oval:org.mitre.oval:def:23708 | ||
Title: | DSA-2873-1 file - several | ||
Description: | Several vulnerabilities have been found in file, a file type classification tool. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2873-1 CVE-2014-2270 CVE-2013-7345 | Version: | 5 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/Linux 7 Debian GNU/kFreeBSD 6.0 Debian GNU/kFreeBSD 7 | Product(s): | file |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:24159 | |||
Oval ID: | oval:org.mitre.oval:def:24159 | ||
Title: | USN-2254-1 -- php5 vulnerabilities | ||
Description: | Several security issues were fixed in PHP. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-2254-1 CVE-2014-0185 CVE-2014-0237 CVE-2014-0238 CVE-2014-4049 | Version: | 3 |
Platform(s): | Ubuntu 14.04 Ubuntu 13.10 Ubuntu 12.04 Ubuntu 10.04 | Product(s): | php5 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:24930 | |||
Oval ID: | oval:org.mitre.oval:def:24930 | ||
Title: | USN-2254-2 -- php5 updates | ||
Description: | An improvement was made for PHP FPM environments. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-2254-2 CVE-2014-0185 CVE-2014-0237 CVE-2014-0238 CVE-2014-4049 | Version: | 3 |
Platform(s): | Ubuntu 14.04 Ubuntu 13.10 | Product(s): | php5 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:24951 | |||
Oval ID: | oval:org.mitre.oval:def:24951 | ||
Title: | DSA-2961-1 php5 - security update | ||
Description: | It was discovered that PHP, a general-purpose scripting language commonly used for web application development, is vulnerable to a heap-based buffer overflow in the DNS TXT record parsing. A malicious server or man-in-the-middle attacker could possibly use this flaw to execute arbitrary code as the PHP interpreter if a PHP application uses dns_get_record() to perform a DNS query. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2961-1 CVE-2014-4049 | Version: | 3 |
Platform(s): | Debian GNU/Linux 7.0 Debian GNU/kFreeBSD 7.0 | Product(s): | php5 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:25274 | |||
Oval ID: | oval:org.mitre.oval:def:25274 | ||
Title: | USN-2278-1 -- file vulnerabilities | ||
Description: | File could be made to crash or hang if it processed specially crafted data. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-2278-1 CVE-2013-7345 CVE-2014-0207 CVE-2014-3478 CVE-2014-3479 CVE-2014-3480 CVE-2014-3487 CVE-2014-3538 | Version: | 3 |
Platform(s): | Ubuntu 14.04 Ubuntu 13.10 Ubuntu 12.04 Ubuntu 10.04 | Product(s): | file |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:26455 | |||
Oval ID: | oval:org.mitre.oval:def:26455 | ||
Title: | DSA-3021-1 file - security update | ||
Description: | Multiple security issues have been found in file, a tool to determine a file type. These vulnerabilities allow remote attackers to cause a denial of service, via resource consumption or application crash. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-3021-1 CVE-2014-0207 CVE-2014-0237 CVE-2014-0238 CVE-2014-3478 CVE-2014-3479 CVE-2014-3480 CVE-2014-3487 CVE-2014-3538 CVE-2014-3587 | Version: | 3 |
Platform(s): | Debian GNU/Linux 7.0 Debian GNU/kFreeBSD 7.0 | Product(s): | file |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:26689 | |||
Oval ID: | oval:org.mitre.oval:def:26689 | ||
Title: | DSA-3008-1 php5 - security update | ||
Description: | Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-3008-1 CVE-2014-3538 CVE-2014-3587 CVE-2014-3597 CVE-2014-4670 CVE-2013-7345 CVE-2014-4049 | Version: | 3 |
Platform(s): | Debian GNU/Linux 7.0 Debian GNU/kFreeBSD 7.0 | Product(s): | php5 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:26755 | |||
Oval ID: | oval:org.mitre.oval:def:26755 | ||
Title: | USN-2344-1 -- php5 vulnerabilities | ||
Description: | php5 could be made to crash or run programs if it received specially crafted network traffic. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-2344-1 CVE-2014-3587 CVE-2014-3597 | Version: | 3 |
Platform(s): | Ubuntu 14.04 Ubuntu 12.04 Ubuntu 10.04 | Product(s): | php5 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:27096 | |||
Oval ID: | oval:org.mitre.oval:def:27096 | ||
Title: | USN-2369-1 -- file vulnerability | ||
Description: | file could be made to crash or run programs as your login if it opened a specially crafted file. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-2369-1 CVE-2014-3587 | Version: | 3 |
Platform(s): | Ubuntu 14.04 Ubuntu 12.04 Ubuntu 10.04 | Product(s): | file |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:27986 | |||
Oval ID: | oval:org.mitre.oval:def:27986 | ||
Title: | DSA-3021-2 -- file regression update | ||
Description: | Multiple security issues have been found in file, a tool to determine a file type. These vulnerabilities allow remote attackers to cause a denial of service, via resource consumption or application crash. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-3021-2 CVE-2014-0207 CVE-2014-0237 CVE-2014-0238 CVE-2014-3478 CVE-2014-3479 CVE-2014-3480 CVE-2014-3487 CVE-2014-3538 CVE-2014-3587 | Version: | 3 |
Platform(s): | Debian GNU/Linux 7.0 Debian GNU/kFreeBSD 7.0 | Product(s): | file |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:28064 | |||
Oval ID: | oval:org.mitre.oval:def:28064 | ||
Title: | DSA-3008-2 -- php5 regression update | ||
Description: | Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-3008-2 CVE-2014-3538 CVE-2014-3587 CVE-2014-3597 CVE-2014-4670 | Version: | 3 |
Platform(s): | Debian GNU/Linux 7.0 Debian GNU/kFreeBSD 7.0 | Product(s): | php5 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:29235 | |||
Oval ID: | oval:org.mitre.oval:def:29235 | ||
Title: | DSA-2873-2 -- file -- several vulnerabilities | ||
Description: | Several vulnerabilities have been found in file, a file type classification tool. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2873-2 CVE-2014-2270 CVE-2013-7345 | Version: | 3 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 Debian GNU/Linux 7.0 Debian GNU/kFreeBSD 7.0 | Product(s): | file |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2014-07-03 | IAVM : 2014-B-0086 - Multiple Vulnerabilities in PHP Severity : Category I - VMSKEY : V0052897 |
Snort® IPS/IDS
Date | Description |
---|---|
2016-03-14 | PHP fileinfo cdf_read_property_info denial of service attempt RuleID : 36262 - Revision : 3 - Type : SERVER-WEBAPP |
2016-03-14 | PHP fileinfo cdf_read_property_info denial of service attempt RuleID : 36261 - Revision : 3 - Type : SERVER-WEBAPP |
2014-11-16 | PHP DNS parsing heap overflow attempt RuleID : 31460 - Revision : 3 - Type : SERVER-WEBAPP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2016-10-05 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1156.nasl - Type : ACT_GATHER_INFO |
2016-09-19 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-2328-1.nasl - Type : ACT_GATHER_INFO |
2016-09-08 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-2210-1.nasl - Type : ACT_GATHER_INFO |
2016-08-29 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-1638-1.nasl - Type : ACT_GATHER_INFO |
2016-08-12 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_70140f20600711e6a6c314dae9d210b8.nasl - Type : ACT_GATHER_INFO |
2016-06-09 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20160510_file_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2016-05-17 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2016-0760.nasl - Type : ACT_GATHER_INFO |
2016-05-16 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2016-0760.nasl - Type : ACT_GATHER_INFO |
2016-05-16 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2016-0050.nasl - Type : ACT_GATHER_INFO |
2016-05-12 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0760.nasl - Type : ACT_GATHER_INFO |
2015-12-22 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20151119_file_on_SL7_x.nasl - Type : ACT_GATHER_INFO |
2015-12-02 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-2155.nasl - Type : ACT_GATHER_INFO |
2015-11-24 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-2155.nasl - Type : ACT_GATHER_INFO |
2015-11-20 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-2155.nasl - Type : ACT_GATHER_INFO |
2015-04-10 | Name : The remote host is missing a Mac OS X update that fixes multiple security vul... File : macosx_SecUpd2015-004.nasl - Type : ACT_GATHER_INFO |
2015-04-10 | Name : The remote host is missing a Mac OS X update that fixes multiple security vul... File : macosx_10_10_3.nasl - Type : ACT_GATHER_INFO |
2015-03-30 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2015-080.nasl - Type : ACT_GATHER_INFO |
2015-03-26 | Name : The remote Debian host is missing a security update. File : debian_DLA-50.nasl - Type : ACT_GATHER_INFO |
2015-03-26 | Name : The remote Debian host is missing a security update. File : debian_DLA-67.nasl - Type : ACT_GATHER_INFO |
2014-11-05 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3064.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-342.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-332.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-333.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-343.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-367.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-372.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-382.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-393.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-398.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-415.nasl - Type : ACT_GATHER_INFO |
2014-10-03 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2369-1.nasl - Type : ACT_GATHER_INFO |
2014-10-01 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1327.nasl - Type : ACT_GATHER_INFO |
2014-10-01 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-1327.nasl - Type : ACT_GATHER_INFO |
2014-10-01 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-1326.nasl - Type : ACT_GATHER_INFO |
2014-10-01 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1327.nasl - Type : ACT_GATHER_INFO |
2014-10-01 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1326.nasl - Type : ACT_GATHER_INFO |
2014-09-30 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1326.nasl - Type : ACT_GATHER_INFO |
2014-09-18 | Name : The remote host is missing a Mac OS X update that fixes multiple vulnerabilit... File : macosx_10_9_5.nasl - Type : ACT_GATHER_INFO |
2014-09-17 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-546.nasl - Type : ACT_GATHER_INFO |
2014-09-12 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-172.nasl - Type : ACT_GATHER_INFO |
2014-09-12 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-167.nasl - Type : ACT_GATHER_INFO |
2014-09-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2344-1.nasl - Type : ACT_GATHER_INFO |
2014-09-10 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3021.nasl - Type : ACT_GATHER_INFO |
2014-09-03 | Name : The remote Fedora host is missing a security update. File : fedora_2014-9684.nasl - Type : ACT_GATHER_INFO |
2014-09-03 | Name : The remote Fedora host is missing a security update. File : fedora_2014-9679.nasl - Type : ACT_GATHER_INFO |
2014-08-30 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201408-11.nasl - Type : ACT_GATHER_INFO |
2014-08-30 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201408-08.nasl - Type : ACT_GATHER_INFO |
2014-08-22 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3008.nasl - Type : ACT_GATHER_INFO |
2014-08-19 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_d2a892b9260511e49da000a0986f28c4.nasl - Type : ACT_GATHER_INFO |
2014-08-07 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-149.nasl - Type : ACT_GATHER_INFO |
2014-08-07 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1013.nasl - Type : ACT_GATHER_INFO |
2014-08-07 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1012.nasl - Type : ACT_GATHER_INFO |
2014-08-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1013.nasl - Type : ACT_GATHER_INFO |
2014-08-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1012.nasl - Type : ACT_GATHER_INFO |
2014-08-01 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-146.nasl - Type : ACT_GATHER_INFO |
2014-07-25 | Name : The remote web server uses a version of PHP that is affected by multiple vuln... File : php_5_5_15.nasl - Type : ACT_GATHER_INFO |
2014-07-16 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2278-1.nasl - Type : ACT_GATHER_INFO |
2014-07-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2276-1.nasl - Type : ACT_GATHER_INFO |
2014-07-10 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-130.nasl - Type : ACT_GATHER_INFO |
2014-07-08 | Name : The remote Fedora host is missing a security update. File : fedora_2014-7782.nasl - Type : ACT_GATHER_INFO |
2014-07-06 | Name : The remote Fedora host is missing a security update. File : fedora_2014-7992.nasl - Type : ACT_GATHER_INFO |
2014-07-01 | Name : The remote Fedora host is missing a security update. File : fedora_2014-7765.nasl - Type : ACT_GATHER_INFO |
2014-06-27 | Name : The remote web server is running a version of PHP that is affected by multipl... File : php_5_5_14.nasl - Type : ACT_GATHER_INFO |
2014-06-27 | Name : The remote web server is running a version of PHP that is affected by multipl... File : php_5_4_30.nasl - Type : ACT_GATHER_INFO |
2014-06-26 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2254-2.nasl - Type : ACT_GATHER_INFO |
2014-06-26 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-443.nasl - Type : ACT_GATHER_INFO |
2014-06-24 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2254-1.nasl - Type : ACT_GATHER_INFO |
2014-06-17 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2961.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-270.nasl - Type : ACT_GATHER_INFO |
2014-04-23 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-323.nasl - Type : ACT_GATHER_INFO |
2014-04-22 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2014-111-02.nasl - Type : ACT_GATHER_INFO |
2014-04-16 | Name : The remote Fedora host is missing a security update. File : fedora_2014-4767.nasl - Type : ACT_GATHER_INFO |
2014-04-16 | Name : The remote Fedora host is missing a security update. File : fedora_2014-4735.nasl - Type : ACT_GATHER_INFO |
2014-04-11 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-075.nasl - Type : ACT_GATHER_INFO |
2014-04-10 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-073.nasl - Type : ACT_GATHER_INFO |
2014-03-27 | Name : The remote Fedora host is missing a security update. File : fedora_2014-4340.nasl - Type : ACT_GATHER_INFO |
2014-03-12 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2873.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-08-28 09:25:45 |
|
2014-08-26 00:25:01 |
|
2014-08-23 13:27:49 |
|
2014-08-23 09:27:00 |
|
2014-08-21 17:23:38 |
|
2014-08-21 09:23:30 |
|