[Bug 813115] [NEW] CVE-2011-2202

2011-07-19 Thread Shaun Duncan
*** This bug is a security vulnerability *** Public security bug reported: Release 5.3.6-11ubuntu1 of php5 main/rfc1867.c requires patch released at http://svn.php.net/viewvc?view=revisionrevision=312103 that prevents file path injection vulnerability. ** Affects: php5 (Ubuntu) Importance:

[Bug 813110] [NEW] CVE-2011-1938

2011-07-19 Thread Shaun Duncan
*** This bug is a security vulnerability *** Public security bug reported: PHP version 5.3.6 (5.3.6-11ubuntu1) contains a security flaw that allows a potential buffer overflow with function socket_connect. Patch should be applied via http://svn.php.net/viewvc?view=revisionrevision=311369 **