~ubuntu-branches/ubuntu/hardy/php5/hardy-updates

Viewing all changes in revision 47.

  • Committer: Package Import Robot
  • Author(s): Marc Deslauriers
  • Date: 2012-09-12 11:51:06 UTC
  • Revision ID: package-import@ubuntu.com-20120912115106-ugiaqvav3s8zrmpm
Tags: 5.2.4-2ubuntu5.26
* SECURITY UPDATE: HTTP response-splitting issue with %0D sequences
  - debian/patches/CVE-2011-1398.patch: properly handle %0D and NUL in
    main/SAPI.c.
  - CVE-2011-1398
  - CVE-2012-4388
* SECURITY UPDATE: denial of service and possible code execution via
  _php_stream_scandir function (LP: #1028064)
  - debian/patches/CVE-2012-2688.patch: prevent overflow in
    main/streams/streams.c.
  - CVE-2012-2688
* SECURITY UPDATE: denial of service via PDO extension crafted parameter
  - debian/patches/CVE-2012-3450.patch: improve logic in 
    ext/pdo/pdo_sql_parser.re, regenerate ext/pdo/pdo_sql_parser.c, add
    test to ext/pdo_mysql/tests/bug_61755.phpt.
  - CVE-2012-3450

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: