|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2005-0525: php DoS | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Ludwig Nussel <lnussel> |
| Component: | Incidents | Assignee: | Michal Čihař <mcihar> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P5 - None | CC: | security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | All | ||
| Whiteboard: | CVE-2005-0525: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Bug Depends on: | 76868 | ||
| Bug Blocks: | |||
|
Description
Ludwig Nussel
2005-04-04 07:42:40 UTC
It looks like following patches should address this issue, can somebody confirm this? php4 branch: http://cvs.php.net/diff.php/php-src/ext/standard/image.c?r1=1.72.2.15&r2=1.72.2.16&ty=h php5 branch: http://cvs.php.net/diff.php/php-src/ext/standard/image.c?r1=1.98.2.3&r2=1.98.2.4&ty=h Looks like patches for this issue, yes. SM-Tracker-807 Fixed packages submitted. Including fix for bug #72441. which subpackages are affected? One header file has been modified, so if will be quite huge list. All SAPI suppackages, devel and modules including that header are: mod_php4 (all subpackages): mod_php4, mod_php4-aolserver, mod_php4-core, mod_php4-devel, mod_php4-servlet, apache2-mod_php4 php4: php4, apache2-mod_php4, php4-fastcgi, php4-servlet, php4-devel, php4-sysvshm, php4-sysvmsg, php4-session php5: php5, apache2-mod_php5, php5-fastcgi, php5-devel, php5-sysvshm, php5-sysvmsg php4-sysvmsg doesn't exist Oh sorry, this extension seems not to be built at all for php4, I just checked sources. patchinfos submitted qa test failed, please clarify whether it's apache's or php's fault. see also #76868. After looking at that bug, it's neither apache nor php fault. php works only with prefork MPM and there seems to be used worker. Is same issue with qa tests? released updates CVE-2005-0525: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) |