Bugzilla – Bug 64657
VUL-0: CVE-2004-0959: php4 updates missing?
Last modified: 2021-11-08 10:14:45 UTC
I just checked the new 9.2-ftp tree (on ftp.gwdg.de) and found out, that there are new php4 rpms with sec fixes (see diff). Now I wonder, why there haven't been any you updates yet ;) cthiel@t41p:~> diff -ur php4-4.3.8-8.changelog php4-4.3.8-8.2.changelog --- php4-4.3.8-8.changelog 2005-01-07 22:35:53.890271768 +0100 +++ php4-4.3.8-8.2.changelog 2005-01-07 22:35:25.719554368 +0100 @@ -1,3 +1,7 @@ +* Do Dez 16 2004 - tcrhak@suse.cz + +- fixed several vulnerabilities (bug 63635, patch secfix1) + * Di Okt 05 2004 - pmladek@suse.cz - added /usr/lib/php/sce_install to prerequires of php4-swf; it is in the cthiel@t41p:~>
<!-- SBZ_reproduce --> n/a
because they do not have the full patch set required. becuase they have not passed our QA. because theyu are still work in progress. Andreas, how could this happen? I thought the ftp tree was mastered from the GA master?
Well, check http://ftp.gwdg.de/pub/linux/suse/ftp.suse.com/suse/i386/9.2/ChangeLog, it doesn't really look like GA ;)
Btw: RedHat already released php4 updates (I can't verify if they worked on the same issues, you'r working on right now): Red Hat Security Advisory Synopsis: Updated php packages fix security issues and bugs Advisory ID: RHSA-2004:687-01 Advisory URL: https://rhn.redhat.com/errata/RHSA-2004-687.html Issue date: 2004-12-21 Updated on: 2004-12-21 Product: Red Hat Enterprise Linux Keywords: PHP Obsoletes: RHBA-2004:272 CVE Names: CAN-2004-0958 CAN-2004-0959 CAN-2004-1018 CAN-2004-1019 CAN-2004-1065
yes, i know redhat did. but with 3 weeks christmas shutdown, and other product work we have not finished the php4 update yet. and now the next high critical kernel problem which has precedence. the php4 on ftp is at least somewhat safer as the previous one.
Sure, I'm not blaming you... now that we have "somewhat safer" php rpms to use for updates, it's ok with me ;)
But it ia a very critical point from the sight of the chiefs of gwdg,de, regarding our SLES-8 installations (several 100). This latency is bad for business. The relative SUSE latency, that is the point... So please struggle on, it it against the enemy.
Marcus, let's sit together some time next week and discuss these issues. Christoph, Eberhard: The update will go out after all issues have been fixed and properly tested, there's no need to keep this bugreport open for tracking.
CVE-2004-0959: CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:N/I:P/A:N)