Bug #15736 Updated: Security Exploit

From: Date: Fri, 08 Mar 2002 01:00:38 +0000
Subject: Bug #15736 Updated: Security Exploit
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-1974@lists.php.net to get a copy of this message
ID: 15736 Updated by: phobo@paradise.net.nz Reported By: n2wog@usa.net Status: Closed Bug Type: Unknown/Other Function Operating System: All UNIX PHP Version: 4.1.1 New Comment: PHP 4.1.2's existance should be reported on the Front Page, perhaps simply stating "offering a number of important security fixes" ? Other people like me have to write things like this: http://www.youngit.org.nz/xmb/viewthread.php?tid=89#pid642 Previous Comments: ------------------------------------------------------------------------ [2002-02-28 23:06:50] spinaltapx@yahoo.com What is the command to install this PHP 4.0.6 patch? Solarix 8x86 doesn't have a "patch -u" option... I also tried: patch -p1 rfc1867.c.diff-4.0.6.PHPpatch patch -c rfc1867.c.diff-4.0.6.PHPpatch patch -irfc1867.c.diff-4.0.6.PHPpatch # ls -laF -rw-r--r-- 1 bin bin 6802 Feb 28 18:21 rfc1867.c.diff-4.0.6.PHPpatch -rw-r--r-- 1 bin bin 310 Feb 28 19:44 rfc1867.h -rw-r--r-- 1 bin bin 310 Sep 9 2000 rfc1867.h.prePHPpatch Help! Thanks guys. ------------------------------------------------------------------------ [2002-02-28 18:18:05] sniper@php.net I was wrong, the exploit is fixed. Rasmus fixed just one segfault. ------------------------------------------------------------------------ [2002-02-28 12:46:48] jflemer@php.net Shouldn't the patch on the downloads page also include this patch by Rasmus? http://cvs.php.net/diff.php/php4/main/rfc1867.c?r1=1.71.2.2&r2=1.71.2.3&ty=u ------------------------------------------------------------------------ [2002-02-28 02:27:52] sniper@php.net ..and I take this back, it's fixed in CVS but not in any release. ------------------------------------------------------------------------ [2002-02-28 02:11:04] sniper@php.net This bug has already been fixed in the latest released version of PHP, which you can download at http://www.php.net/downloads.php ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/15736 -- Edit this bug report at http://bugs.php.net/?id=15736&edit=1

« previous php.bugs (#1974) next »