[php-maint] Bug#571974: php5: [suhosin] buffer overflows could overwrite read-only settings

sean finney seanius at debian.org
Sun Feb 28 17:45:50 UTC 2010


Package: php5
Version: 5.3.1-5
Severity: important

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

posted here:

http://www.suspekt.org/2010/02/27/debian-breaks-suhosin-security-feature/

i'd prefer to keep all the soap-box grandstanding in the comments there,
and the relevant discussion towards fixing the problem here.

- -- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.32-2-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages php5 depends on:
ii  libapache2-mod-php5           5.3.1-5    server-side, HTML-embedded scripti
ii  php5-common                   5.3.1-5    Common files for packages built fr

php5 recommends no packages.

php5 suggests no packages.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iD4DBQFLiqvKynjLPm522B0RAtk+AJ9yET86lyprEaSnsTlrWXSZnEll4QCWOVBN
iTuvMBzjDfQp0lf+7i561A==
=AIdQ
-----END PGP SIGNATURE-----





More information about the pkg-php-maint mailing list