php5: CVE-2013-4248: invalid handling of certs with null bytes

Related Vulnerabilities: CVE-2013-4248  

Debian Bug report logs - #719765
php5: CVE-2013-4248: invalid handling of certs with null bytes

version graph

Reported by: Henri Salo <henri@nerv.fi>

Date: Thu, 15 Aug 2013 05:06:02 UTC

Severity: important

Tags: fixed-upstream, security

Found in versions php5/5.5.1+dfsg-2, php5/5.4.4-14+deb7u2, php5/5.5.1+dfsg-1, php5/5.3.3-7+squeeze14

Fixed in versions php5/5.5.3+dfsg-1, php5/5.4.4-14+deb7u4, php5/5.3.3-7+squeeze17

Done: Ondřej Surý <ondrej@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#719765; Package php5. (Thu, 15 Aug 2013 05:06:06 GMT) (full text, mbox, link).


Acknowledgement sent to Henri Salo <henri@nerv.fi>:
New Bug report received and forwarded. Copy sent to Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Thu, 15 Aug 2013 05:06:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Henri Salo <henri@nerv.fi>
To: submit@bugs.debian.org
Subject: php5: CVE-2013-4248: invalid handling of certs with null bytes
Date: Thu, 15 Aug 2013 08:01:50 +0300
[Message part 1 (text/plain, inline)]
Package: php5
Version: 5.5.1+dfsg-2
Severity: important
Tags: security, fixed-upstream

CVE request: http://openwall.com/lists/oss-security/2013/08/14/4
Upstream fixes:
    http://git.php.net/?p=php-src.git;a=commit;h=dcea4ec698dcae39b7bba6f6aa08933cbfee6755
    http://git.php.net/?p=php-src.git;a=commit;h=2874696a5a8d46639d261571f915c493cd875897

Update affected versions as needed.

---
Henri Salo
[signature.asc (application/pgp-signature, inline)]

Marked as found in versions php5/5.5.1+dfsg-1. Request was from Ondřej Surý <ondrej@debian.org> to control@bugs.debian.org. (Fri, 23 Aug 2013 14:39:04 GMT) (full text, mbox, link).


Marked as fixed in versions php5/5.5.3+dfsg-1. Request was from Ondřej Surý <ondrej@debian.org> to control@bugs.debian.org. (Fri, 23 Aug 2013 14:39:05 GMT) (full text, mbox, link).


Marked as found in versions php5/5.4.4-14+deb7u2. Request was from Ondřej Surý <ondrej@debian.org> to control@bugs.debian.org. (Fri, 23 Aug 2013 14:39:07 GMT) (full text, mbox, link).


Marked as found in versions php5/5.3.3-7+squeeze14. Request was from Ondřej Surý <ondrej@debian.org> to control@bugs.debian.org. (Fri, 23 Aug 2013 14:39:07 GMT) (full text, mbox, link).


Reply sent to Ondřej Surý <ondrej@debian.org>:
You have taken responsibility. (Mon, 26 Aug 2013 22:21:17 GMT) (full text, mbox, link).


Notification sent to Henri Salo <henri@nerv.fi>:
Bug acknowledged by developer. (Mon, 26 Aug 2013 22:21:17 GMT) (full text, mbox, link).


Message #18 received at 719765-close@bugs.debian.org (full text, mbox, reply):

From: Ondřej Surý <ondrej@debian.org>
To: 719765-close@bugs.debian.org
Subject: Bug#719765: fixed in php5 5.4.4-14+deb7u4
Date: Mon, 26 Aug 2013 22:17:07 +0000
Source: php5
Source-Version: 5.4.4-14+deb7u4

We believe that the bug you reported is fixed in the latest version of
php5, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 719765@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ondřej Surý <ondrej@debian.org> (supplier of updated php5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Fri, 23 Aug 2013 16:26:59 +0200
Source: php5
Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm libphp5-embed php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-imap php5-interbase php5-intl php5-ldap php5-mcrypt php5-mysql php5-mysqlnd php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl
Architecture: source all amd64
Version: 5.4.4-14+deb7u4
Distribution: stable
Urgency: low
Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>
Changed-By: Ondřej Surý <ondrej@debian.org>
Description: 
 libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module)
 libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo
 libphp5-embed - HTML-embedded scripting language (Embedded SAPI library)
 php-pear   - PEAR - PHP Extension and Application Repository
 php5       - server-side, HTML-embedded scripting language (metapackage)
 php5-cgi   - server-side, HTML-embedded scripting language (CGI binary)
 php5-cli   - command-line interpreter for the php5 scripting language
 php5-common - Common files for packages built from the php5 source
 php5-curl  - CURL module for php5
 php5-dbg   - Debug symbols for PHP5
 php5-dev   - Files for PHP5 module development
 php5-enchant - Enchant module for php5
 php5-fpm   - server-side, HTML-embedded scripting language (FPM-CGI binary)
 php5-gd    - GD module for php5
 php5-gmp   - GMP module for php5
 php5-imap  - IMAP module for php5
 php5-interbase - interbase/firebird module for php5
 php5-intl  - internationalisation module for php5
 php5-ldap  - LDAP module for php5
 php5-mcrypt - MCrypt module for php5
 php5-mysql - MySQL module for php5
 php5-mysqlnd - MySQL module for php5 (Native Driver)
 php5-odbc  - ODBC module for php5
 php5-pgsql - PostgreSQL module for php5
 php5-pspell - pspell module for php5
 php5-recode - recode module for php5
 php5-snmp  - SNMP module for php5
 php5-sqlite - SQLite module for php5
 php5-sybase - Sybase / MS SQL Server module for php5
 php5-tidy  - tidy module for php5
 php5-xmlrpc - XML-RPC module for php5
 php5-xsl   - XSL module for php5
Closes: 719765
Changes: 
 php5 (5.4.4-14+deb7u4) stable; urgency=low
 .
   * [CVE-2013-4248]: Fix handling of certs with NULL bytes (Closes: #719765)
Checksums-Sha1: 
 0958b7a6445a59586a145a60e653ccdd5f4e9249 3738 php5_5.4.4-14+deb7u4.dsc
 edaa4db05b7e39b797e19971e3e698c6ba8dd66b 206059 php5_5.4.4-14+deb7u4.diff.gz
 d237b4c86ae98986803bbaf73f75d3aa8af6d223 1026 php5_5.4.4-14+deb7u4_all.deb
 9e707863db079960fb92916c8a7e7936195a210f 369230 php-pear_5.4.4-14+deb7u4_all.deb
 617da53bd81a7c47969834178adb066e058795aa 587282 php5-common_5.4.4-14+deb7u4_amd64.deb
 ea0dacf9ab22a67c9ae44a8ebbc5507d56344bc6 2665206 libapache2-mod-php5_5.4.4-14+deb7u4_amd64.deb
 2dd5245cc41f32b574a52c55941b3708f5e318c4 2663194 libapache2-mod-php5filter_5.4.4-14+deb7u4_amd64.deb
 8c749d48e3f03fb6f850b2dac90ad7a682bfd5eb 5099730 php5-cgi_5.4.4-14+deb7u4_amd64.deb
 07bf54f5ef72f9950fe89564ef8d9189cabac1d5 2557112 php5-cli_5.4.4-14+deb7u4_amd64.deb
 2af0fee5da2034309a8b55bef7031f3403908bd1 2589768 php5-fpm_5.4.4-14+deb7u4_amd64.deb
 a90ec5963da1995587ae704d99d75f2fcf644c4b 2661528 libphp5-embed_5.4.4-14+deb7u4_amd64.deb
 e9dcd2b7b128140d82350bd7a5bfaf967021a34e 497416 php5-dev_5.4.4-14+deb7u4_amd64.deb
 745d8cc01414f0da3c2de129b1d483eee91ecf17 15958708 php5-dbg_5.4.4-14+deb7u4_amd64.deb
 8a55f56cc498b1ca4bbe55cfb28df248aca886dd 29096 php5-curl_5.4.4-14+deb7u4_amd64.deb
 b0f8b8f84e608ebf8c1d1c15df07908772fc0d80 9938 php5-enchant_5.4.4-14+deb7u4_amd64.deb
 f38a1a20a68fab8af9f719fec190e9fe111562a1 35710 php5-gd_5.4.4-14+deb7u4_amd64.deb
 7244a22f67885f0e6d4223c831031a4d634c598a 17170 php5-gmp_5.4.4-14+deb7u4_amd64.deb
 dd398f6c051d627dd099fda6dfec73ec2a804099 35608 php5-imap_5.4.4-14+deb7u4_amd64.deb
 3c0e15b636c460ce164c4adbb323854d95683386 49620 php5-interbase_5.4.4-14+deb7u4_amd64.deb
 5a00ed1495bd6c1beb0f7ef1c5b50046e11a9d19 71970 php5-intl_5.4.4-14+deb7u4_amd64.deb
 646c234190c8e585d2697d6ee0dc7e17c808eb54 21772 php5-ldap_5.4.4-14+deb7u4_amd64.deb
 e953c61ad67013595e10938d79fcb02d37da21dc 16090 php5-mcrypt_5.4.4-14+deb7u4_amd64.deb
 0e43c937f6cb30f122c4fedd1315175d29105712 80858 php5-mysql_5.4.4-14+deb7u4_amd64.deb
 ac790c92d78e69d89af5b551e871e42df881edd2 162730 php5-mysqlnd_5.4.4-14+deb7u4_amd64.deb
 f886b0095268030410fd7e509ce19c617f73c88d 36408 php5-odbc_5.4.4-14+deb7u4_amd64.deb
 fc035e3fd11fd5f9c4ed97601fbe1a8966a85b66 61070 php5-pgsql_5.4.4-14+deb7u4_amd64.deb
 56d1eb7e985d832a4abf837ea3b2061728539acc 8912 php5-pspell_5.4.4-14+deb7u4_amd64.deb
 c24fa1f3d6830f9bfd27f51073fe89f56e09974d 5208 php5-recode_5.4.4-14+deb7u4_amd64.deb
 74ddfe3416abc36e13e9a0128dcfa92675d06e5e 21810 php5-snmp_5.4.4-14+deb7u4_amd64.deb
 23a514b886eb939003a7f90259b28d0a923c4885 30354 php5-sqlite_5.4.4-14+deb7u4_amd64.deb
 112b29476a583ae1c2c6df20166d731752639ac7 28456 php5-sybase_5.4.4-14+deb7u4_amd64.deb
 4fe34536370e04aab790608ddae5f5e904e4160d 19606 php5-tidy_5.4.4-14+deb7u4_amd64.deb
 cd9a7f68b5932dc75059f7866938c6f68d5ef213 36298 php5-xmlrpc_5.4.4-14+deb7u4_amd64.deb
 90498885a80401a3590cf2ca779c0347fa65f532 15422 php5-xsl_5.4.4-14+deb7u4_amd64.deb
Checksums-Sha256: 
 326641ac456b0069356957bfc040fad36ad4f29af3d9b39411c24925f3838707 3738 php5_5.4.4-14+deb7u4.dsc
 ca85f906add18a255e69430bd66cc0d6cea0c576a5880ce82863b1829d9e32b7 206059 php5_5.4.4-14+deb7u4.diff.gz
 a496d285388da699f8475f2e6e0984dca3743a97b3c00f12ccc146a6b7f73139 1026 php5_5.4.4-14+deb7u4_all.deb
 a4e944d6f74521df4f1992be380210f4aa03ca5d4fcc5b6940d2a51ed257f296 369230 php-pear_5.4.4-14+deb7u4_all.deb
 0e867a3d2bf73f61110f14ec47962fd836561f42c1049ec83b850fce39fdbeda 587282 php5-common_5.4.4-14+deb7u4_amd64.deb
 7bdd126451096da1ecb32cbf8dddbf8af8919134fa61d1e3097d5ccd3b92f3d3 2665206 libapache2-mod-php5_5.4.4-14+deb7u4_amd64.deb
 d5c4292c45144a5617e888513a7182d8a00516a062b4182f9f82b72d0b624e64 2663194 libapache2-mod-php5filter_5.4.4-14+deb7u4_amd64.deb
 ddf4ec75a55a36f97c36e076baf8061b0bfa63151e1a5c5ef5a613a04cccc108 5099730 php5-cgi_5.4.4-14+deb7u4_amd64.deb
 f80049ffee40728fb3adee64dd012a48661c29e0dc2cf3c805fce271c856357d 2557112 php5-cli_5.4.4-14+deb7u4_amd64.deb
 d9dce2dbd4fbded68f06f950be0d7937a043297125cd9e94caf0988bb1108b5b 2589768 php5-fpm_5.4.4-14+deb7u4_amd64.deb
 299e6268c18d02e7c7fd33cffa5b02d7df306c9a6e2566107da51559273ad017 2661528 libphp5-embed_5.4.4-14+deb7u4_amd64.deb
 3a417656941d73358d0412c292aa7db73dd0595ec56ee14e12b38299f8f8feab 497416 php5-dev_5.4.4-14+deb7u4_amd64.deb
 0296a41b2cd6c51d0425d198834f3b73967532f1cc357dc83b32073007055758 15958708 php5-dbg_5.4.4-14+deb7u4_amd64.deb
 3896de3c36d963d604394a1a3d27f8fcdeef812062a320a41a82cc28eb80c885 29096 php5-curl_5.4.4-14+deb7u4_amd64.deb
 bcbd025734e805b54585ae9884605504f8d0b9cd25ae8b2322ef306d91ce3dcb 9938 php5-enchant_5.4.4-14+deb7u4_amd64.deb
 03f65275d97d130ef23284a46216059031c501da37506b792d4fe951a3c521d1 35710 php5-gd_5.4.4-14+deb7u4_amd64.deb
 6fbe16a01ffad4989ff98deaedf2de55067cbd6590d68cfbece59b41b93c5ec1 17170 php5-gmp_5.4.4-14+deb7u4_amd64.deb
 2d623c59e15fa925bcd3720754588681c241a4334ca028b58532e633e5cd343e 35608 php5-imap_5.4.4-14+deb7u4_amd64.deb
 5e93064a6c1abaea374a3b4edc4afe56847e6a4d9f6f2cae3ab6848bfdddd3d1 49620 php5-interbase_5.4.4-14+deb7u4_amd64.deb
 e26086f450ae7f6484e264d4254c3b15f72c9abe6f940130c6d9d266431f23f1 71970 php5-intl_5.4.4-14+deb7u4_amd64.deb
 322b08c633c6a848264ba0b4a917f019c13deb9aac69549d355fd6a5e6d27fca 21772 php5-ldap_5.4.4-14+deb7u4_amd64.deb
 a28dce1aa045a16fb91f69540d341c4f483afad18b5e24841da67991f09dd2b1 16090 php5-mcrypt_5.4.4-14+deb7u4_amd64.deb
 e86b02a721b9bd2590091565c55d2b15e7246e890e1375958cc29df32b4b5bb2 80858 php5-mysql_5.4.4-14+deb7u4_amd64.deb
 5c6081c33ef84392e0eb32e2671991b5996506e16b056552c6a0b6816d68e657 162730 php5-mysqlnd_5.4.4-14+deb7u4_amd64.deb
 88424ed0b43104eeffbc282c19fe6065f19de113ba5b8626d68855e0f03abd8c 36408 php5-odbc_5.4.4-14+deb7u4_amd64.deb
 81448f323da5e062801c2dfb4139ce7cf74ce6eab3502874329f251e5042658f 61070 php5-pgsql_5.4.4-14+deb7u4_amd64.deb
 e8d973faf147aacc9f9423d7e93fbb86e2bc3b4f3dbcb88958504c72ebb08210 8912 php5-pspell_5.4.4-14+deb7u4_amd64.deb
 5aa2ae8a95e983045b6d0942163f9a44456254c6a17792c3f5e9202f9e8ccb69 5208 php5-recode_5.4.4-14+deb7u4_amd64.deb
 94c60634cc0b3efb06f02a694ca525f6beb6c316e854ba1ab43176d63293b4a2 21810 php5-snmp_5.4.4-14+deb7u4_amd64.deb
 e38dffa893a0b67f0289fa839c1f9ab8d4cb1682e9d3f75f29425a28681df74d 30354 php5-sqlite_5.4.4-14+deb7u4_amd64.deb
 d255796149e9934120fbb651577c42b393a6da9b98155bae037b54101f3fbb89 28456 php5-sybase_5.4.4-14+deb7u4_amd64.deb
 6f6ca5101e202f1fed32f2dd9175186d8d3147776e3c16ac61d4a25a921c9ffa 19606 php5-tidy_5.4.4-14+deb7u4_amd64.deb
 cac70f853b1d867daff97c0851c37ed1da0540db8bbeb9993b9681ad0a1aa268 36298 php5-xmlrpc_5.4.4-14+deb7u4_amd64.deb
 52f67bd2bc29b64e5bda1d3fa167691097d17b3e70d94db13413f58bf84be194 15422 php5-xsl_5.4.4-14+deb7u4_amd64.deb
Files: 
 bd268360038d29abe431c2f022fd0411 3738 php optional php5_5.4.4-14+deb7u4.dsc
 82acd0f5ff8f773e87aa3c64e539de12 206059 php optional php5_5.4.4-14+deb7u4.diff.gz
 e95e82bcd42e92b37f68944750783f6c 1026 php optional php5_5.4.4-14+deb7u4_all.deb
 0db4d071d55f6db71685b5061100bc16 369230 php optional php-pear_5.4.4-14+deb7u4_all.deb
 929d613fb1ca5f4d41a88b3e407fa218 587282 php optional php5-common_5.4.4-14+deb7u4_amd64.deb
 a7e0addb59b5e5de9488d59f88b8c574 2665206 httpd optional libapache2-mod-php5_5.4.4-14+deb7u4_amd64.deb
 abf9a55bd56a81b11fd9de80c9d230f7 2663194 httpd extra libapache2-mod-php5filter_5.4.4-14+deb7u4_amd64.deb
 4c695b69aae5846ac6beb2635d365ad1 5099730 php optional php5-cgi_5.4.4-14+deb7u4_amd64.deb
 50ca47acb31e79ae848bc20abc0a0175 2557112 php optional php5-cli_5.4.4-14+deb7u4_amd64.deb
 6aa1f22f360c708c45982da0bfefd38e 2589768 php optional php5-fpm_5.4.4-14+deb7u4_amd64.deb
 c286b01717f40c067aa56e03610bd5de 2661528 php optional libphp5-embed_5.4.4-14+deb7u4_amd64.deb
 439ef18d313d6df0393737f764b28f00 497416 php optional php5-dev_5.4.4-14+deb7u4_amd64.deb
 999f404206f8ab74753b05436520fb94 15958708 debug extra php5-dbg_5.4.4-14+deb7u4_amd64.deb
 f99c5de0337944c3c98b073f62d66747 29096 php optional php5-curl_5.4.4-14+deb7u4_amd64.deb
 796b0b1eb40e8fe954602d4047967064 9938 php optional php5-enchant_5.4.4-14+deb7u4_amd64.deb
 266ba279cc2fa62f18c48728c5babc19 35710 php optional php5-gd_5.4.4-14+deb7u4_amd64.deb
 c70256d34e16695ba2579363e358df14 17170 php optional php5-gmp_5.4.4-14+deb7u4_amd64.deb
 a856dfad157839b97902f7b533b7c3a5 35608 php optional php5-imap_5.4.4-14+deb7u4_amd64.deb
 391828a9b0ae2fe5619d571c7befede7 49620 php optional php5-interbase_5.4.4-14+deb7u4_amd64.deb
 073f9efe98106ffc6beb8e5fcc1bfaeb 71970 php optional php5-intl_5.4.4-14+deb7u4_amd64.deb
 17fa3768852dd6e0673e1ecfde48eca9 21772 php optional php5-ldap_5.4.4-14+deb7u4_amd64.deb
 ae24246d5130cde4ef6e342aee85944d 16090 php optional php5-mcrypt_5.4.4-14+deb7u4_amd64.deb
 8740dc2cca80c6493237b87cdc0f3005 80858 php optional php5-mysql_5.4.4-14+deb7u4_amd64.deb
 15d0c4df8ad3440d7fce746834261e85 162730 php extra php5-mysqlnd_5.4.4-14+deb7u4_amd64.deb
 2251df3bb4db5572cdc2560108ef1cfd 36408 php optional php5-odbc_5.4.4-14+deb7u4_amd64.deb
 543db9267ac79240cabee1a4ace8d3df 61070 php optional php5-pgsql_5.4.4-14+deb7u4_amd64.deb
 59f703c46f5e8d46a2d8d84bc517f7ed 8912 php optional php5-pspell_5.4.4-14+deb7u4_amd64.deb
 ec1f3ac8667a42a9f462bbfd85e8fc6f 5208 php optional php5-recode_5.4.4-14+deb7u4_amd64.deb
 b5bf3ed66cabbdf00d36d3aabc61e0ce 21810 php optional php5-snmp_5.4.4-14+deb7u4_amd64.deb
 10b4504f51a146a858346b55155a39c6 30354 php optional php5-sqlite_5.4.4-14+deb7u4_amd64.deb
 98281e19ea2f142a49fef2b5ff70b7c5 28456 php optional php5-sybase_5.4.4-14+deb7u4_amd64.deb
 05b7e4be8eb2ad8a4105380843bde310 19606 php optional php5-tidy_5.4.4-14+deb7u4_amd64.deb
 b1886b6bf545451416a8d0baefa7de5e 36298 php optional php5-xmlrpc_5.4.4-14+deb7u4_amd64.deb
 d111dae4bfc1a9d4b6801e11844893c8 15422 php optional php5-xsl_5.4.4-14+deb7u4_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlIa+pQACgkQ9OZqfMIN8nMKSQCePUKN9knkB9M7VnQWfrNV7bef
DOAAniPQaZjIi9TyYEUvKKGi6HvAv6UO
=Cc4Q
-----END PGP SIGNATURE-----




Reply sent to Ondřej Surý <ondrej@debian.org>:
You have taken responsibility. (Mon, 26 Aug 2013 22:21:21 GMT) (full text, mbox, link).


Notification sent to Henri Salo <henri@nerv.fi>:
Bug acknowledged by developer. (Mon, 26 Aug 2013 22:21:21 GMT) (full text, mbox, link).


Message #23 received at 719765-close@bugs.debian.org (full text, mbox, reply):

From: Ondřej Surý <ondrej@debian.org>
To: 719765-close@bugs.debian.org
Subject: Bug#719765: fixed in php5 5.3.3-7+squeeze17
Date: Mon, 26 Aug 2013 22:18:01 +0000
Source: php5
Source-Version: 5.3.3-7+squeeze17

We believe that the bug you reported is fixed in the latest version of
php5, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 719765@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ondřej Surý <ondrej@debian.org> (supplier of updated php5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Fri, 23 Aug 2013 16:57:14 +0200
Source: php5
Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-imap php5-interbase php5-intl php5-ldap php5-mcrypt php5-mysql php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl
Architecture: source all amd64
Version: 5.3.3-7+squeeze17
Distribution: squeeze-security
Urgency: low
Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>
Changed-By: Ondřej Surý <ondrej@debian.org>
Description: 
 libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module)
 libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo
 php-pear   - PEAR - PHP Extension and Application Repository
 php5       - server-side, HTML-embedded scripting language (metapackage)
 php5-cgi   - server-side, HTML-embedded scripting language (CGI binary)
 php5-cli   - command-line interpreter for the php5 scripting language
 php5-common - Common files for packages built from the php5 source
 php5-curl  - CURL module for php5
 php5-dbg   - Debug symbols for PHP5
 php5-dev   - Files for PHP5 module development
 php5-enchant - Enchant module for php5
 php5-gd    - GD module for php5
 php5-gmp   - GMP module for php5
 php5-imap  - IMAP module for php5
 php5-interbase - interbase/firebird module for php5
 php5-intl  - internationalisation module for php5
 php5-ldap  - LDAP module for php5
 php5-mcrypt - MCrypt module for php5
 php5-mysql - MySQL module for php5
 php5-odbc  - ODBC module for php5
 php5-pgsql - PostgreSQL module for php5
 php5-pspell - pspell module for php5
 php5-recode - recode module for php5
 php5-snmp  - SNMP module for php5
 php5-sqlite - SQLite module for php5
 php5-sybase - Sybase / MS SQL Server module for php5
 php5-tidy  - tidy module for php5
 php5-xmlrpc - XML-RPC module for php5
 php5-xsl   - XSL module for php5
Closes: 719765
Changes: 
 php5 (5.3.3-7+squeeze17) squeeze-security; urgency=low
 .
   * [CVE-2013-4248]: Fix handling of certs with NULL bytes (Closes: #719765)
Checksums-Sha1: 
 5ce72fd3e9ef2a72d21034d9976d81292224c811 2798 php5_5.3.3-7+squeeze17.dsc
 aff2dcea2ac463983b341a8921b89079ff7e43d2 262391 php5_5.3.3-7+squeeze17.diff.gz
 48ad166322b8ae371f33c4db0e8fe5c835036a24 1062 php5_5.3.3-7+squeeze17_all.deb
 3e662d6003e2fa463ba25a6e957d0e5703aff8ef 362948 php-pear_5.3.3-7+squeeze17_all.deb
 34880d69f2a901fcd0e7aa9be3484f1658768a69 556068 php5-common_5.3.3-7+squeeze17_amd64.deb
 1d68559ad470dd1b6f897de1b08ec4868bed8d18 3038932 libapache2-mod-php5_5.3.3-7+squeeze17_amd64.deb
 47340bdb7277836ab0434a29113018ce14ee4850 3038048 libapache2-mod-php5filter_5.3.3-7+squeeze17_amd64.deb
 ee9a81fbf83acc163d866289910d69366a07f3b1 5890948 php5-cgi_5.3.3-7+squeeze17_amd64.deb
 8652a3a6e8965dc7107eb1aa3cbffa84329eddbe 2944002 php5-cli_5.3.3-7+squeeze17_amd64.deb
 2ae8cf9b5c2e377e3fead4f2ba7d7472a28b915f 409668 php5-dev_5.3.3-7+squeeze17_amd64.deb
 fc08f4f0652ecedf77b7e2f8c21b5d4403b55d4d 10305852 php5-dbg_5.3.3-7+squeeze17_amd64.deb
 846ea29543a19ae729b102cbc41aca8a380ebdb9 27056 php5-curl_5.3.3-7+squeeze17_amd64.deb
 05b00f589be7fdd18d177e59345353897d32833f 8984 php5-enchant_5.3.3-7+squeeze17_amd64.deb
 4cd996a83ec5bc456cfa212bade2b7ce48ff2a58 39168 php5-gd_5.3.3-7+squeeze17_amd64.deb
 f8ff24e3568146b934fe2d5c9e5e61e0b649d0e9 16442 php5-gmp_5.3.3-7+squeeze17_amd64.deb
 e2da5c381fbad9959e39bbb8f9d7d8a4dee04d1a 35040 php5-imap_5.3.3-7+squeeze17_amd64.deb
 90ba83c6dae50554138de45047c28b80bf096da6 49372 php5-interbase_5.3.3-7+squeeze17_amd64.deb
 262f624119b6a002207e08782961c2482adc6b86 59632 php5-intl_5.3.3-7+squeeze17_amd64.deb
 f350044f0e6b684734d6465e4a9c8f5ca4f450ba 19812 php5-ldap_5.3.3-7+squeeze17_amd64.deb
 33841b8b7bda60cf931c584b1a797201424fd581 15204 php5-mcrypt_5.3.3-7+squeeze17_amd64.deb
 5bb18d4ea7035bf78683033b90d421cd3da76bc7 76696 php5-mysql_5.3.3-7+squeeze17_amd64.deb
 1fc76b079b057e0b642339a33ba003e4829d7e0f 35650 php5-odbc_5.3.3-7+squeeze17_amd64.deb
 fb11bf3249f23ad64e44d7b4008631453a5a5c57 60040 php5-pgsql_5.3.3-7+squeeze17_amd64.deb
 f9410db6a823d192f1edb79896accc1c04f439df 8256 php5-pspell_5.3.3-7+squeeze17_amd64.deb
 a8bf56e44feaf2bf82d1df0f0794adffb6391feb 4326 php5-recode_5.3.3-7+squeeze17_amd64.deb
 3d2250a700190d026efaafa5082c3b117176a5a4 11332 php5-snmp_5.3.3-7+squeeze17_amd64.deb
 539b425e6e7296882293a8e2ece70fb42c0b9a93 55952 php5-sqlite_5.3.3-7+squeeze17_amd64.deb
 96c3f0a862394045ed92b1a7662cd5905a588a3d 26518 php5-sybase_5.3.3-7+squeeze17_amd64.deb
 cd4f6002f293931c672628b7903140e78632bf84 18350 php5-tidy_5.3.3-7+squeeze17_amd64.deb
 1cd4bfd924888bf047231ebae39c27d16b85ae62 34754 php5-xmlrpc_5.3.3-7+squeeze17_amd64.deb
 bc1e2ac6c78e50b45247eb544b01fb85ba2db94c 14142 php5-xsl_5.3.3-7+squeeze17_amd64.deb
Checksums-Sha256: 
 16460325753857a058182588058870a1479d75653a5a32844bd4415aba1ad0f4 2798 php5_5.3.3-7+squeeze17.dsc
 aa07fd64dfbbf7d8a48cbd87c6c1ca32f93c350804c1e985b9bb5ad59b67da4b 262391 php5_5.3.3-7+squeeze17.diff.gz
 fcde90b8c0d38d39776d7210f6a3f75fe0a0c85a92622b917e77cbd7c28a2f41 1062 php5_5.3.3-7+squeeze17_all.deb
 2da50fcfbcd3eeebc893f17cd1bdb788f0120a605c279e266769a7f57bf11d45 362948 php-pear_5.3.3-7+squeeze17_all.deb
 7ccf6d8a1386fe77e254e21435f59fae76211d2687ebf162941bc0428ac02cb2 556068 php5-common_5.3.3-7+squeeze17_amd64.deb
 e121d2177783dae2112d1bf48ca5075d33092b66fe9e87756f720f45f837e11c 3038932 libapache2-mod-php5_5.3.3-7+squeeze17_amd64.deb
 8fff2051f8234f08ab55f1ab3542b161cbb1502b3e5085e347779fc9a161034c 3038048 libapache2-mod-php5filter_5.3.3-7+squeeze17_amd64.deb
 d12d88adc40df72890c577b67d803640c3b487c6d32124b9be3f1d7660a310b9 5890948 php5-cgi_5.3.3-7+squeeze17_amd64.deb
 5483fe1f9715d3600b197a97674ae3f5d43b5caac65d8d08b27a3ee5f08eca28 2944002 php5-cli_5.3.3-7+squeeze17_amd64.deb
 7ef0198e5a139168f549db9bbb5e15d85b241982e880291da07bfc559e7d6e16 409668 php5-dev_5.3.3-7+squeeze17_amd64.deb
 143574ac8211b5f4b29600eb875de7fea073832d16350b190155eb27f236c568 10305852 php5-dbg_5.3.3-7+squeeze17_amd64.deb
 bee4e538d2ae78d1104331fab1cee47aa477adf958a49db6557538a2b8c2b2bf 27056 php5-curl_5.3.3-7+squeeze17_amd64.deb
 6f2e0a5328e10987c721e76cad4dba3cf4ebbd038e2e3c271500453cba765ab1 8984 php5-enchant_5.3.3-7+squeeze17_amd64.deb
 1cb0588f69c44ba26c0c340d6215bb5927e020611ad7a168efd640e12474b896 39168 php5-gd_5.3.3-7+squeeze17_amd64.deb
 5a4523acd0dc5cde3dd3dd75e217744dfa4f3fcf3536c29483b1056102050ab7 16442 php5-gmp_5.3.3-7+squeeze17_amd64.deb
 a9dbb47c878a5a00aab38d5dca013c06eced39d6492147238e6509370d6454c9 35040 php5-imap_5.3.3-7+squeeze17_amd64.deb
 935d157a44711ee9deddecc6ac619642346aae5e8579e088cabdc76adb1e8573 49372 php5-interbase_5.3.3-7+squeeze17_amd64.deb
 e50d04dfecfdeb5bccb1486272f680e6ae2f9a43563d2cc6ef7972da9434ad19 59632 php5-intl_5.3.3-7+squeeze17_amd64.deb
 d8a98edf0537adfeba42d493846d5703177efd0ecf2d5d4cdf38fc31f94d9d21 19812 php5-ldap_5.3.3-7+squeeze17_amd64.deb
 5a2011599dbad46aba165ac570404c2a3a608164924bc79676d1c0ddbf6bd334 15204 php5-mcrypt_5.3.3-7+squeeze17_amd64.deb
 be9e7fafe0e05b10f535fa20aa6e8a0d4164381ba9bb58bf39fd1aae6ff6c7ea 76696 php5-mysql_5.3.3-7+squeeze17_amd64.deb
 4dcbec34e8a942ab968f08b7f7ca4f2f7a74c636160bf33c008c90cdbf4c0e59 35650 php5-odbc_5.3.3-7+squeeze17_amd64.deb
 ae2dc8591e4bd173de939845bd8402e99e4be0a6adc1a2bc2f8887f36b078468 60040 php5-pgsql_5.3.3-7+squeeze17_amd64.deb
 4db24b4bedd9dddc54f37b653f52d8457b99ae77aab799981a036d81e0c057df 8256 php5-pspell_5.3.3-7+squeeze17_amd64.deb
 2e75be03b6a931b8c5c025899c92dad9e232a54540ae24380aa78b294350d4c7 4326 php5-recode_5.3.3-7+squeeze17_amd64.deb
 5646ddd96216a1f26a63171773fa830479c4e4de165c2ba5cf7f36e25ad2e103 11332 php5-snmp_5.3.3-7+squeeze17_amd64.deb
 58a5d0edcbe8b64e33b9d5727018ab2aae53f1f1a82e0498e418e461cedc5f76 55952 php5-sqlite_5.3.3-7+squeeze17_amd64.deb
 c96519fd011755c41595b6ba3a9d331aaa43c29f466b734c1a4b8377b637218f 26518 php5-sybase_5.3.3-7+squeeze17_amd64.deb
 fdad08d07b2da8449f9f421cddd5a0bd507d24083de425f3baeb237fbac5dea5 18350 php5-tidy_5.3.3-7+squeeze17_amd64.deb
 10d2c2ff31fcdaba91030b3fd2012de222483bee35ef4f2b48dccbb552c8f547 34754 php5-xmlrpc_5.3.3-7+squeeze17_amd64.deb
 54a056910d26f5138f41cc55e9f54feaadc1531206811ba7b38583a0ed260e68 14142 php5-xsl_5.3.3-7+squeeze17_amd64.deb
Files: 
 00ce3ff855231dc18c0503f6498a508c 2798 php optional php5_5.3.3-7+squeeze17.dsc
 b416af1f53a97fd40d2d316103364ec0 262391 php optional php5_5.3.3-7+squeeze17.diff.gz
 7ba344744c1cc8205fb315d0e93a1abb 1062 php optional php5_5.3.3-7+squeeze17_all.deb
 8f2fd4474d435263fd756161c85e4ecd 362948 php optional php-pear_5.3.3-7+squeeze17_all.deb
 4417c675ee3938e6b98c3ea3a2747e4a 556068 php optional php5-common_5.3.3-7+squeeze17_amd64.deb
 53fb30d28866b5b119cef1785dd202b0 3038932 httpd optional libapache2-mod-php5_5.3.3-7+squeeze17_amd64.deb
 bd29de430052453bebcf026f0be86d5e 3038048 httpd optional libapache2-mod-php5filter_5.3.3-7+squeeze17_amd64.deb
 3f1bbff723ff3810822d459f0ec3cd81 5890948 php optional php5-cgi_5.3.3-7+squeeze17_amd64.deb
 9005e108cd309fe821fc31d553586885 2944002 php optional php5-cli_5.3.3-7+squeeze17_amd64.deb
 bae89e66250e2b258abee79656ea0420 409668 php optional php5-dev_5.3.3-7+squeeze17_amd64.deb
 4cebc827c7e30b2a77a0389e6865e263 10305852 debug extra php5-dbg_5.3.3-7+squeeze17_amd64.deb
 24e044fa5599978198dd20f9e1362ccc 27056 php optional php5-curl_5.3.3-7+squeeze17_amd64.deb
 0378304e3fa8c3c729cc7bcb3fdc4f2c 8984 php optional php5-enchant_5.3.3-7+squeeze17_amd64.deb
 974fb73474e98a5c4fdab98962b7f173 39168 php optional php5-gd_5.3.3-7+squeeze17_amd64.deb
 c3e5a0b21b10deef7c9ed8af87c2b805 16442 php optional php5-gmp_5.3.3-7+squeeze17_amd64.deb
 6a8e2cc25b4ae63d87d83403b65015c4 35040 php optional php5-imap_5.3.3-7+squeeze17_amd64.deb
 1171357b1bb48a425f44e1a694e00f61 49372 php optional php5-interbase_5.3.3-7+squeeze17_amd64.deb
 5562b6844195efe51622ddf2d69bf399 59632 php optional php5-intl_5.3.3-7+squeeze17_amd64.deb
 df670b85f9391ee65cbdd02f2d797ce5 19812 php optional php5-ldap_5.3.3-7+squeeze17_amd64.deb
 e76b34e10c9627f7a9def0b83533774b 15204 php optional php5-mcrypt_5.3.3-7+squeeze17_amd64.deb
 4c61eb8f9ae9ea0eb5ca4e6919811c8e 76696 php optional php5-mysql_5.3.3-7+squeeze17_amd64.deb
 3531a0cbf727cee9a7671c13b64df5c5 35650 php optional php5-odbc_5.3.3-7+squeeze17_amd64.deb
 48d1568d96c8752031beb751bad2b462 60040 php optional php5-pgsql_5.3.3-7+squeeze17_amd64.deb
 d5a317bf2b761d9b68cc4911a2da7293 8256 php optional php5-pspell_5.3.3-7+squeeze17_amd64.deb
 28364740418a0edca1e9c8f43c763b16 4326 php optional php5-recode_5.3.3-7+squeeze17_amd64.deb
 6f26c8d2a2ad8339fe1f8e42d6d02257 11332 php optional php5-snmp_5.3.3-7+squeeze17_amd64.deb
 6f3659de8d14110ffd79c79ef5dc424b 55952 php optional php5-sqlite_5.3.3-7+squeeze17_amd64.deb
 f70209886dd42a06c2ac7be7bff3b615 26518 php optional php5-sybase_5.3.3-7+squeeze17_amd64.deb
 c2032d8566d1fdf80616b4a5952e858b 18350 php optional php5-tidy_5.3.3-7+squeeze17_amd64.deb
 a3cfed68c6d970f0ab7dd7444d428cd2 34754 php optional php5-xmlrpc_5.3.3-7+squeeze17_amd64.deb
 b6e9c5c789fbd174d928df6c57ddddff 14142 php optional php5-xsl_5.3.3-7+squeeze17_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlIXk9IACgkQ9OZqfMIN8nNXtACfeABVVb9XPVANiWPZq85b2ywV
j+kAn2fpJZA+TWEJEtBmMEchXSer8ylk
=XHFc
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sat, 05 Oct 2013 07:36:17 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 14:13:58 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.