|
Subject: GLSA: phpsysinfo (200311-06) Newsgroups: gmane.linux.gentoo.announce Date: 2003-11-24 17:43:42 GMT (4 years, 46 weeks, 2 days and 26 minutes ago)
---------------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200311-06
---------------------------------------------------------------------------
GLSA: 200311-06
package: dev-php/phpsysinfo
summary: phpSysInfo directory traversal
severity: normal
Gentoo bug: 26782
date: 2003-11-22
CVE: CAN-2003-0536
exploit: local
affected: <=2.1
fixed: >=2.1-r1
DESCRIPTION:
phpSysInfo contains two vulnerabilities which could allow local files to be
read or arbitrary PHP code to be executed, under the privileges of the web
server process.
SOLUTION:
It is recommended that all Gentoo Linux users who are running
dev-php/phpsysinfo upgrade to the fixed version:
emerge sync
emerge '>=dev-php/phpsysinfo-2.1-r1'
emerge clean
--
Andrea Barisani <lcars <at> gentoo.org> .*.
Gentoo Linux Infrastructure Developer V
( )
GPG-Key 0xC9EE0905 http://dev.gentoo.org/~lcars/pubkey.asc ( )
491D E9E0 3875 0EC9 10DD 150B CAA9 2C7D C9EE 0905 ^^_^^
|
|
|