GLSA-201110-06 : PHP: Multiple vulnerabilities

critical Nessus Plugin ID 56459

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-201110-06 (PHP: Multiple vulnerabilities)

Multiple vulnerabilities have been discovered in PHP. Please review the CVE identifiers referenced below for details.
Impact :

A context-dependent attacker could execute arbitrary code, obtain sensitive information from process memory, bypass intended access restrictions, or cause a Denial of Service in various ways.
A remote attacker could cause a Denial of Service in various ways, bypass spam detections, or bypass open_basedir restrictions.
Workaround :

There is no known workaround at this time.

Solution

All PHP users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=dev-lang/php-5.3.8'

See Also

https://security.gentoo.org/glsa/201110-06

Plugin Details

Severity: Critical

ID: 56459

File Name: gentoo_GLSA-201110-06.nasl

Version: 1.11

Type: local

Published: 10/12/2011

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.3

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:php, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/10/2011

Reference Information

CVE: CVE-2006-7243, CVE-2009-5016, CVE-2010-1128, CVE-2010-1129, CVE-2010-1130, CVE-2010-1860, CVE-2010-1861, CVE-2010-1862, CVE-2010-1864, CVE-2010-1866, CVE-2010-1868, CVE-2010-1914, CVE-2010-1915, CVE-2010-1917, CVE-2010-2093, CVE-2010-2094, CVE-2010-2097, CVE-2010-2100, CVE-2010-2101, CVE-2010-2190, CVE-2010-2191, CVE-2010-2225, CVE-2010-2484, CVE-2010-2531, CVE-2010-2950, CVE-2010-3062, CVE-2010-3063, CVE-2010-3064, CVE-2010-3065, CVE-2010-3436, CVE-2010-3709, CVE-2010-3710, CVE-2010-3870, CVE-2010-4150, CVE-2010-4409, CVE-2010-4645, CVE-2010-4697, CVE-2010-4698, CVE-2010-4699, CVE-2010-4700, CVE-2011-0420, CVE-2011-0421, CVE-2011-0708, CVE-2011-0752, CVE-2011-0753, CVE-2011-0755, CVE-2011-1092, CVE-2011-1148, CVE-2011-1153, CVE-2011-1464, CVE-2011-1466, CVE-2011-1467, CVE-2011-1468, CVE-2011-1469, CVE-2011-1470, CVE-2011-1471, CVE-2011-1657, CVE-2011-1938, CVE-2011-2202, CVE-2011-2483, CVE-2011-3182, CVE-2011-3189, CVE-2011-3267, CVE-2011-3268

GLSA: 201110-06