Page 1 of 1

PHP Vulnerability Fixes in All Supported Ubuntu OSes

PostPosted: Thu Mar 14, 2013 9:58 am
by Micro
On March 13, Canonical published in a security notice details about a GnuTLS vulnerability for its Ubuntu 12.10, Ubuntu 12.04 LTS, Ubuntu 11.10, Ubuntu 10.04 LTS, and Ubuntu 8.04 LTS operating systems. According to Canonical, PHP could be made to expose sensitive information over the network. It was discovered that PHP incorrectly handled XML external entities in SOAP WSDL files. A remote attacker could use this flaw to read arbitrary files off the server. The security flaws can be fixed if you upgrade your system(s) to the latest php5 package, specific to each distribution. To apply the update, run the Update Manager:
Ubuntu 12.10:
php5 5.4.6-1ubuntu1.2
Ubuntu 12.04 LTS:
php5 5.3.10-1ubuntu3.6
Ubuntu 11.10:
php5 5.3.6-13ubuntu3.10
Ubuntu 10.04 LTS:
php5 5.3.2-1ubuntu4.19
Ubuntu 8.04 LTS:
php5 5.2.4-2ubuntu5.27