Bug #15736 Updated: Security Exploit
| From: | phobo at paradise dot net dot nz | Date: | Fri, 08 Mar 2002 01:00:38 +0000 |
| Subject: | Bug #15736 Updated: Security Exploit | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-1974@lists.php.net to get a copy of this message | ||
ID: 15736
Updated by: phobo@paradise.net.nz
Reported By: n2wog@usa.net
Status: Closed
Bug Type: Unknown/Other Function
Operating System: All UNIX
PHP Version: 4.1.1
New Comment:
PHP 4.1.2's existance should be reported on the Front Page, perhaps
simply stating "offering a number of important security fixes" ?
Other people like me have to write things like this:
http://www.youngit.org.nz/xmb/viewthread.php?tid=89#pid642
Previous Comments:
------------------------------------------------------------------------
[2002-02-28 23:06:50] spinaltapx@yahoo.com
What is the command to install this PHP 4.0.6 patch? Solarix 8x86
doesn't have a "patch -u" option... I also tried:
patch -p1 rfc1867.c.diff-4.0.6.PHPpatch
patch -c rfc1867.c.diff-4.0.6.PHPpatch
patch -irfc1867.c.diff-4.0.6.PHPpatch
# ls -laF
-rw-r--r-- 1 bin bin 6802 Feb 28 18:21
rfc1867.c.diff-4.0.6.PHPpatch
-rw-r--r-- 1 bin bin 310 Feb 28 19:44 rfc1867.h
-rw-r--r-- 1 bin bin 310 Sep 9 2000
rfc1867.h.prePHPpatch
Help!
Thanks guys.
------------------------------------------------------------------------
[2002-02-28 18:18:05] sniper@php.net
I was wrong, the exploit is fixed. Rasmus fixed just one
segfault.
------------------------------------------------------------------------
[2002-02-28 12:46:48] jflemer@php.net
Shouldn't the patch on the downloads page also include this patch by
Rasmus?
http://cvs.php.net/diff.php/php4/main/rfc1867.c?r1=1.71.2.2&r2=1.71.2.3&ty=u
------------------------------------------------------------------------
[2002-02-28 02:27:52] sniper@php.net
..and I take this back, it's fixed in CVS but not in any
release.
------------------------------------------------------------------------
[2002-02-28 02:11:04] sniper@php.net
This bug has already been fixed in the latest released version of
PHP, which you can download at http://www.php.net/downloads.php
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/15736
--
Edit this bug report at http://bugs.php.net/?id=15736&edit=1