Linux Mandrake Security Team escribió: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > ________________________________________________________________________ > > Linux-Mandrake Security Update Advisory > ________________________________________________________________________ > > Package name: php > Date: January 18th, 2001 > Advisory ID: MDKSA-2001:013 > > Affected versions: 7.2 > ________________________________________________________________________ > > Problem Description: > > There are two security problems with php4 as shipped in Linux-Mandrake > 7.2. It is possible to specify PHP directives on a per-directory basis > under Apache and a remote attacker could carefully craft an HTTP > request that would cause the next page to be served with the wrong > values for these directives. The second problem is that although PHP > may be installed, it can be activated and deactivated on a per- > directory or per-virtual host basis using the "engine=on" or > "engine=off" directive. PHP can "leak" the "engine=off" setting to > other virtual hosts on the same machine, effectively disabling PHP for > those hosts and resulting in PHP source code being sent to the client > instead of being executed on the server. These vulnerabilities are > corrected in PHP 4.0.4pl1. > ________________________________________________________________________ > > Please verify the update prior to upgrading to ensure the integrity of > the downloaded package. You can do this with the command: > rpm --checksig package.rpm > You can get the GPG public key of the Linux-Mandrake Security Team at > http://www.linux-mandrake.com/en/security/RPM-GPG-KEYS > If you use MandrakeUpdate, the verification of md5 checksum and GPG > signature is performed automatically for you. > > Linux-Mandrake 7.2: > f54b0ce745c1903794522b04eba99576 7.2/RPMS/mod_php-4.0.4pl1-1.1mdk.i586.rpm > c39a3f03e58b3234af7f95e0b1ebbb4d 7.2/RPMS/php-4.0.4pl1-1.1mdk.i586.rpm > b74cd72804ec86a6287dcee0c938eb1a 7.2/RPMS/php-dba_gdbm_db2-4.0.4pl1-1.1mdk.i586.rpm > d29d2c054274a98726da22c2fa2e02c6 7.2/RPMS/php-devel-4.0.4pl1-1.1mdk.i586.rpm > c20961189744753ee91a6fd834a937c0 7.2/RPMS/php-gd-4.0.4pl1-1.1mdk.i586.rpm > e9d3312f15355741243450c7d74872d9 7.2/RPMS/php-imap-4.0.4pl1-1.1mdk.i586.rpm > a68b22849371aaf36fa8e3c1d549dbbf 7.2/RPMS/php-ldap-4.0.4pl1-1.1mdk.i586.rpm > ff06eb076f3e8673b39dc5f260320ee7 7.2/RPMS/php-manual-4.0.4pl1-1.1mdk.i586.rpm > 70dc4d1e9175a7ec6dfa1647e7db81ba 7.2/RPMS/php-mysql-4.0.4pl1-1.1mdk.i586.rpm > 91f93f9f40b4aa44774a35af508ce17a 7.2/RPMS/php-pgsql-4.0.4pl1-1.1mdk.i586.rpm > 4f67c0695fa61c1d76f1cba399441398 7.2/RPMS/php-readline-4.0.4pl1-1.1mdk.i586.rpm > 81e7aae1084066990f95a82a2fd07d26 7.2/SRPMS/php-4.0.4pl1-1.1mdk.src.rpm > ________________________________________________________________________ > > To upgrade automatically, use MandrakeUpdate. > > If you want to upgrade manually, download the updated package from one > of our FTP server mirrors and upgrade with "rpm -Fvh *.rpm". > > You can download the updates directly from one of the mirror sites > listed at: > > http://www.linux-mandrake.com/en/ftp.php3. > > Updated packages are available in the "updates/[ver]/RPMS/" directory. > For example, if you are looking for an updated RPM package for > Linux-Mandrake 7.2, look for it in "updates/7.2/RPMS/". Updated source > RPMs are available as well, but you generally do not need to download > them. > > Please be aware that sometimes it takes the mirrors a few hours to > update. > > You can view other security advisories for Linux-Mandrake at: > > http://www.linux-mandrake.com/en/security/ > > If you want to report vulnerabilities, please contact > > [EMAIL PROTECTED] > ________________________________________________________________________ > > Linux-Mandrake has two security-related mailing list services that > anyone can subscribe to: > > [EMAIL PROTECTED] > > Linux-Mandrake's security announcements mailing list. Only > announcements are sent to this list and it is read-only. > > [EMAIL PROTECTED] > > Linux-Mandrake's security discussion mailing list. This list is open > to anyone to discuss Linux-Mandrake security specifically and Linux > security in general. > > To subscribe to either list, send a message to > [EMAIL PROTECTED] > with "subscribe [listname]" in the body of the message. > > To remove yourself from either list, send a message to > [EMAIL PROTECTED] > with "unsubscribe [listname]" in the body of the message. > > To get more information on either list, send a message to > [EMAIL PROTECTED] > with "info [listname]" in the body of the message. > > Optionally, you can use the web interface to subscribe to or unsubscribe > from either list: > > http://www.linux-mandrake.com/en/flists.php3#security > ________________________________________________________________________ > > Type Bits/KeyID Date User ID > pub 1024D/22458A98 2000-07-10 Linux Mandrake Security Team > <[EMAIL PROTECTED]> > > - -----BEGIN PGP PUBLIC KEY BLOCK----- > Version: GnuPG v1.0.1 (GNU/Linux) > Comment: For info see http://www.gnupg.org > > mQGiBDlp594RBAC2tDozI3ZgQsE7XwxurJCJrX0L5vx7SDByR5GHDdWekGhdiday > L4nfUax+SeR9SCoCgTgPW1xB8vtQc8/sinJlMjp9197a2iKM0FOcPlkpa3HcOdt7 > WKJqQhlMrHvRcsivzcgqjH44GBBJIT6sygUF8k0lU6YnMHj5MPc/NGWt8wCg9vKo > P0l5QVAFSsHtqcU9W8cc7wMEAJzQsAlnvPXDBfBLEH6u7ptWFdp0GvbSuG2wRaPl > hynHvRiE01ZvwbJZXsPsKm1z7uVoW+NknKLunWKB5axrNXDHxCYJBzY3jTeFjsqx > PFZkIEAQphLTkeXXelAjQ5u9tEshPswEtMvJvUgNiAfbzHfPYmq8D6x5xOw1IySg > 2e/LBACxr2UJYCCB2BZ3p508mAB0RpuLGukq+7UWiOizy+kSskIBg2O7sQkVY/Cs > iyGEo4XvXqZFMY39RBdfm2GY+WB/5NFiTOYJRKjfprP6K1YbtsmctsX8dG+foKsD > LLFs7OuVfaydLQYp1iiN6D+LJDSMPM8/LCWzZsgr9EKJ8NXiyrQ6TGludXggTWFu > ZHJha2UgU2VjdXJpdHkgVGVhbSA8c2VjdXJpdHlAbGludXgtbWFuZHJha2UuY29t > PohWBBMRAgAWBQI5aefeBAsKBAMDFQMCAxYCAQIXgAAKCRCaqNDQIkWKmK6LAKCy > /NInDsaMSI+WHwrquwC5PZrcnQCeI+v3gUDsNfQfiKBvQSANu1hdulq5AQ0EOWnn > 7xAEAOQlTVY4TiNo5V/iP0J1xnqjqlqZsU7yEBKo/gZz6/+hx75RURe1ebiJ9F77 > 9FQbpJ9Epz1KLSXvq974rnVb813zuGdmgFyk+ryA/rTR2RQ8h+EoNkwmATzRxBXV > Jb57fFQjxOu4eNjZAtfII/YXb0uyXXrdr5dlJ/3eXrcO4p0XAAMFBACCxo6Z269s > +A4v8C6Ui12aarOQcCDlV8cVG9LkyatU3FNTlnasqwo6EkaP572448weJWwN6SCX > Vl+xOYLiK0hL/6Jb/O9Agw75yUVdk+RMM2I4fNEi+y4hmfMh2siBv8yEkEvZjTcl > 3TpkTfzYky85tu433wmKaLFOv0WjBFSikohGBBgRAgAGBQI5aefvAAoJEJqo0NAi > RYqYid0AoJgeWzXrEdIClBOSW5Q6FzqJJyaqAKC0Y9YI3UFlE4zSIGjcFlLJEJGX > lA== > =WxWn > - -----END PGP PUBLIC KEY BLOCK----- > > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.0.4 (GNU/Linux) > Comment: For info see http://www.gnupg.org > > iD8DBQE6Z2U6mqjQ0CJFipgRAhh7AJ92PvOdyNE09naT5Ftoj4MvyzJX3gCgkMa6 > d8SqWH/jfL0DFXcRCNHCows= > =HwMA > -----END PGP SIGNATURE----- -- ¿Desea desuscribirse? Escriba a [EMAIL PROTECTED] con el tema "unsubscribe".
