PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities
April 16, 2012 by Network Security
Filed under Software patches
| Bugtraq ID: | 49241 |
| Class: | Unknown |
| CVE: | CVE-2011-1148 CVE-2011-2483 CVE-2011-2202 CVE-2011-2483 CVE-2011-3267 CVE-2011-3268 CVE-2011-1938 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 18 2011 12:00AM |
| Updated: | Apr 13 2012 04:20PM |
| Credit: | <br>ateusz Kocielski and PHP |
| Vulnerable: | Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Software Development Kit 11 SP1 SuSE SUSE Linux Enterprise Server for VMware 11 SP1 SuSE SUSE Linux Enterprise Server 11 SP2 + Linux kernel 2.6.5 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise Desktop 11 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP4 SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 10 SP4 SuSE SUSE Linux Enterprise 10 SP3 SuSE openSUSE 11.4 SuSE openSUSE 11.3 Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 Red Hat Fedora 16 Red Hat Fedora 15 Red Hat Fedora 14 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server PHP PHP 5.3.6 PHP PHP 5.3.6 PHP PHP 5.3.5 PHP PHP 5.3.2 PHP PHP 5.3.1 PHP PHP 5.3 PHP PHP 5.2.13 PHP PHP 5.2.12 PHP PHP 5.2.11 PHP PHP 5.2.10 PHP PHP 5.2.9 PHP PHP 5.2.8 PHP PHP 5.2.6 PHP PHP 5.2.5 PHP PHP 5.2.4 PHP PHP 5.2.3 PHP PHP 5.2.2 PHP PHP 5.2.1 PHP PHP 5.1.6 + Ubuntu Ubuntu Linux 6.10 sparc + Ubuntu Ubuntu Linux 6.10 powerpc + Ubuntu Ubuntu Linux 6.10 i386 + Ubuntu Ubuntu Linux 6.10 amd64 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 4.4.9 PHP PHP 4.4.8 PHP PHP 4.4.7 PHP PHP 4.4.6 PHP PHP 4.4.5 PHP PHP 4.4.4 PHP PHP 4.4.3 PHP PHP 4.4.2 PHP PHP 4.4.1 PHP PHP 4.4 .0 PHP PHP 4.3.11 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 + S.u.S.E. Linux Personal 9.0 x86_64 + S.u.S.E. Linux Personal 9.0 + Turbolinux Home + Turbolinux Turbolinux 10 F… + Turbolinux Turbolinux Desktop 10.0 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 + Debian Linux 2.2 sparc + Debian Linux 2.2 powerpc + Debian Linux 2.2 IA-32 + Debian Linux 2.2 arm + Debian Linux 2.2 alpha + Debian Linux 2.2 68k + Debian Linux 2.2 + Sun Cobalt Control Station 4100CS + Sun Cobalt Qube3 Japanese 4000WGJ + Sun Cobalt Qube3 Japanese w/ Caching and RAID 4100WGJ + Sun Cobalt Qube3 Japanese w/Caching 4010WGJ + Sun Cobalt RaQ XTR 3500R + Sun Cobalt RaQ XTR Japanese 3500R-ja PHP PHP 4.0.2 PHP PHP 4.0.1 + Sun Cobalt Qube3 4000WG + Sun Cobalt Qube3 w/ Caching and RAID 4100WG + Sun Cobalt Qube3 w/Caching 4010WG + Sun Cobalt RaQ4 3001R + Sun Cobalt RaQ4 Japanese RAID 3100R-ja + Sun Cobalt RaQ4 RAID 3100R PHP PHP 4.0 0 PHP PHP 3.0.18 PHP PHP 3.0.17 + S.u.S.E. Linux 7.1 x86 + S.u.S.E. Linux 7.1 sparc + S.u.S.E. Linux 7.1 ppc + S.u.S.E. Linux 7.1 alpha + S.u.S.E. Linux 7.1 + S.u.S.E. Linux 7.0 sparc + S.u.S.E. Linux 7.0 ppc + S.u.S.E. Linux 7.0 i386 + S.u.S.E. Linux 7.0 alpha + S.u.S.E. Linux 7.0 + Trustix Secure Linux 1.2 + Trustix Secure Linux 1.1 PHP PHP 3.0.16 PHP PHP 3.0.15 PHP PHP 3.0.14 PHP PHP 3.0.13 PHP PHP 3.0.12 PHP PHP 3.0.11 PHP PHP 3.0.10 PHP PHP 3.0.9 PHP PHP 3.0.8 PHP PHP 3.0.7 PHP PHP 3.0.6 PHP PHP 3.0.5 PHP PHP 3.0.4 PHP PHP 3.0.3 PHP PHP 3.0.2 PHP PHP 3.0.1 PHP PHP 3.0 0 PHP PHP 5.3.5 PHP PHP 5.3.4 RC1 PHP PHP 5.3.4 PHP PHP 5.3.3 PHP PHP 5.2.14 PHP PHP 5.2 Oracle Linux 5 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Oracle Enterprise Linux 4 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Kolab Kolab Groupware Server 2.2.4 Kolab Kolab Groupware Server 2.3.2 Kolab Kolab Groupware Server 2.3.1 Gentoo Linux F5 FirePass 6.0.3 F5 FirePass 6.0.2 F5 FirePass 6.0.1 F5 FirePass 7.0 F5 FirePass 6.1 F5 FirePass 6.0.2.3 F5 FirePass 6.0 F5 BigIP Local Traffic Manager (LTM) 8900 10.2.1 HFA3 F5 BigIP Local Traffic Manager (LTM) 6400 10.2.1 HFA3 F5 BigIP Link Controller 10.1 F5 BigIP Link Controller 10.0.1 F5 BigIP Link Controller 10.0 F5 BigIP Global Traffic Manager (GTM) 10.1 F5 BigIP Global Traffic Manager (GTM) 10.0.1 F5 BigIP Global Traffic Manager (GTM) 10.0 F5 BigIP Application Security Manager (ASM) 10.1 F5 BigIP Application Security Manager (ASM) 10.0.1 F5 BigIP Application Security Manager (ASM) 10.0 F5 BIG-IP Protocol Security Manager 10.1 F5 BIG-IP Protocol Security Manager 10.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Message Networking 5.2.1 Avaya Message Networking 5.2.2 Avaya Message Networking 5.2 SP1 Avaya Message Networking 5.2 Avaya Message Networking 3.1 Avaya IP Office Application Server 8.0 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Communication Manager Utility Services 6.1 + Avaya Communication Manager Server DEFINITY Server SI/CS + Avaya Communication Manager Server S8100 + Avaya Communication Manager Server S8300 + Avaya Communication Manager Server S8500 + Avaya Communication Manager Server S8700 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Communication Manager 4.0 Avaya Aura Communication Manager 4.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 4.2.3 Avaya Aura Application Enablement Services 4.2.2 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Avaya Aura Application Enablement Services 4.2 Avaya Aura Application Enablement Services 4.1 Avaya Aura Application Enablement Services 4.0 Apple Mac OS X Server 10.6.6 Apple Mac OS X Server 10.6.5 Apple Mac OS X Server 10.6.5 Apple Mac OS X Server 10.6.4 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac Os X Server 10.7.2 Apple Mac Os X Server 10.7.1 Apple Mac Os X Server 10.7 Apple Mac Os X Server 10.6.8 Apple Mac Os X Server 10.6.7 Apple Mac OS X Server 10.6 Apple Mac OS X 10.6.5 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac Os X 10.7.2 Apple Mac Os X 10.7.1 Apple Mac OS X 10.6 |
| Not Vulnerable: | PHP PHP 5.3.7 Kolab Kolab Groupware Server 2.3.3 Apple Mac Os X Server 10.7.3 Apple Mac Os X 10.7.3 |
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
- Slackware php-5.3.8-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ php-5.3.8-i486-1_slack12.2.tgz
Apple Mac Os X Server 10.7.2
- Apple MacOSXServerUpd10.7.3.dmg
For OS X Lion Server v10.7.2
http://www.apple.com/support/downloads/
MandrakeSoft Enterprise Server 5
- Mandriva glibc-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-devel-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-doc-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-doc-pdf-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-i18ndata-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-profile-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-static-devel-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-utils-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva libecpg8.3_6-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva libpq8.3_5-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva nscd-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva php-suhosin-0.9.32.1-0.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql8.3-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql8.3-contrib-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql8.3-devel-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql8.3-docs-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql8.3-pl-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql8.3-plperl-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql8.3-plpgsql-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql8.3-plpython-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql8.3-pltcl-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql8.3-server-8.3.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Apple Mac Os X 10.7.1
- Apple MacOSXUpdCombo10.7.3.dmg
For OS X Lion v10.7 and v10.7.1
http://www.apple.com/support/downloads/
Mandriva Linux Mandrake 2011
- Mandriva glibc-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-devel-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-doc-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-doc-pdf-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-i18ndata-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-profile-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-static-devel-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva glibc-utils-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva libecpg9.0_6-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva libossp-uuid++16-1.6.2-8.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva libossp-uuid-devel-1.6.2-8.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva libossp-uuid_dce16-1.6.2-8.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva libossp-uuid16-1.6.2-8.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva libpq9.0_5-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva nscd-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva ossp-uuid-1.6.2-8.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva perl-OSSP-uuid-1.6.2-8.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva php-OSSP-uuid-1.6.2-8.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva php-suhosin-0.9.32.1-9.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql-OSSP-uuid-1.6.2-5.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql-OSSP-uuid-1.6.2-8.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql9.0-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql9.0-contrib-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql9.0-devel-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql9.0-docs-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql9.0-pl-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql9.0-plperl-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql9.0-plpgsql-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql9.0-plpython-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql9.0-pltcl-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
- Mandriva postgresql9.0-server-9.0.5-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
Slackware Linux 13.37
- Slackware php-5.3.8-i486-1_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages /php-5.3.8-i486-1_slack13.37.txz
Apple Mac Os X Server 10.6.8
- Apple SecUpdSrvr2012-001.dmg
For Mac OS X Server v10.6.8
http://www.apple.com/support/downloads/



