On The Insider: Miley Cyrus in Sex and the City 2
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 1 of 12:
Next »
I watch with interest
Read about it here :

http://www.ciac.org/ciac/bulletins/p-067.shtml

"PHP Development Team would like to announce the
immediate release of PHP 4.3.10. This is a maintenance
release that in addition to over 30 non-critical bug fixes
addresses several very serious security issues.

These include the following:

CAN-2004-1018 - shmop_write() out of bounds memory
write access.
CAN-2004-1018 - integer overflow/underflow in pack()
and unpack() functions.
CAN-2004-1019 - possible information disclosure, double
free and negative reference index array underflow in
deserialization code.
CAN-2004-1020 - addslashes() not escaping \0 correctly.
CAN-2004-1063 - safe_mode execution directory bypass.
CAN-2004-1064 - arbitrary file access through path
truncation.
CAN-2004-1065 - exif_read_data() overflow on long
sectionname. magic_quotes_gpc could lead to one level
directory traversal with file uploads. "

References CAN-2004-1018, CAN-2004-1020, CAN-2004-
1063, and CAN-2004-1064 were later rejected by CVE
because they were "not considered to be a serious security
issue"

"VULNERABILITY ASSESSMENT: The risk is LOW"

That said I'm interested in how long it takes the community
supported Linux distributions to release a patch.
Particularly for me this is a real test for the Fedora Legacy
Project and Fedora Core 1 handed to it a few months ago.
The clock has started.
Posted by: Richard Flude   Posted on: 12/17/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

I watch with interest  Richard Flude | 12/17/04
And for a laugh  Richard Flude | 12/17/04
Of all MS apps - wordpad  toadlife | 12/18/04
well, consider the source...  linuxoverwindows | 12/18/04
How many times every is Wordpad invoked  FilledOut | 12/18/04
I use it all the time  toadlife | 12/18/04
I should have written that differently  FilledOut | 12/19/04
vim  linuxoverwindows | 12/21/04
More than you may think  AmusedAtItAll | 12/20/04
Hehe, funny post!  NonZealot | 12/21/04
And the process begins  Richard Flude | 12/19/04
Just like a used car salesman...  Da-Man | 12/19/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

Click Here