php5: CVE-2013-6420: memory corruption in openssl_x509_parse()

Related Vulnerabilities: CVE-2013-6420   CVE-2013-6712  

Debian Bug report logs - #731895
php5: CVE-2013-6420: memory corruption in openssl_x509_parse()

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Wed, 11 Dec 2013 06:45:01 UTC

Severity: grave

Tags: patch, security, upstream

Found in versions php5/5.3.3-7+squeeze17, php5/5.4.4-14+deb7u5

Fixed in versions php5/5.5.6+dfsg-2, php5/5.3.3-7+squeeze18, php5/5.5.7+dfsg-1, php5/5.4.4-14+deb7u7

Done: Ondřej Surý <ondrej@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#731895; Package php5. (Wed, 11 Dec 2013 06:45:06 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Wed, 11 Dec 2013 06:45:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: php5: CVE-2013-6420: memory corruption in openssl_x509_parse()
Date: Wed, 11 Dec 2013 07:41:22 +0100
Package: php5
Severity: grave
Tags: security upstream patch

Hi,

the following vulnerability was published for php5.

CVE-2013-6420[0]:
php: memory corruption in openssl_x509_parse()

The upstream commit is found at [1].

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6420
    http://security-tracker.debian.org/tracker/CVE-2013-6420
[1] http://git.php.net/?p=php-src.git;a=commitdiff;h=c1224573c773b6845e83505f717fbf820fc18415

Please adjust the affected versions in the BTS as needed; could you
check if squeeze and wheezy are affected as well?

Regards,
Salvatore



Information forwarded to debian-bugs-dist@lists.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#731895; Package php5. (Wed, 11 Dec 2013 22:36:10 GMT) (full text, mbox, link).


Acknowledgement sent to Lior Kaplan <kaplan@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Wed, 11 Dec 2013 22:36:10 GMT) (full text, mbox, link).


Message #10 received at 731895@bugs.debian.org (full text, mbox, reply):

From: Lior Kaplan <kaplan@debian.org>
To: Salvatore Bonaccorso <carnil@debian.org>, 731895@bugs.debian.org
Subject: Re: [php-maint] Bug#731895: php5: CVE-2013-6420: memory corruption in openssl_x509_parse()
Date: Thu, 12 Dec 2013 00:34:05 +0200
[Message part 1 (text/plain, inline)]
As PHP.net has released the fix also for 5.3 and 5.4 branches, I assume
it's relevant for the both squeeze and wheezy. The problematic code was
there for a long time.

Kaplan


On Wed, Dec 11, 2013 at 8:41 AM, Salvatore Bonaccorso <carnil@debian.org>wrote:

> Package: php5
> Severity: grave
> Tags: security upstream patch
>
> Hi,
>
> the following vulnerability was published for php5.
>
> CVE-2013-6420[0]:
> php: memory corruption in openssl_x509_parse()
>
> The upstream commit is found at [1].
>
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
>
> For further information see:
>
> [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6420
>     http://security-tracker.debian.org/tracker/CVE-2013-6420
> [1]
> http://git.php.net/?p=php-src.git;a=commitdiff;h=c1224573c773b6845e83505f717fbf820fc18415
>
> Please adjust the affected versions in the BTS as needed; could you
> check if squeeze and wheezy are affected as well?
>
> Regards,
> Salvatore
>
> _______________________________________________
> pkg-php-maint mailing list
> pkg-php-maint@lists.alioth.debian.org
> http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-php-maint
>
[Message part 2 (text/html, inline)]

Reply sent to Ondřej Surý <ondrej@debian.org>:
You have taken responsibility. (Thu, 12 Dec 2013 10:54:13 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Thu, 12 Dec 2013 10:54:13 GMT) (full text, mbox, link).


Message #15 received at 731895-close@bugs.debian.org (full text, mbox, reply):

From: Ondřej Surý <ondrej@debian.org>
To: 731895-close@bugs.debian.org
Subject: Bug#731895: fixed in php5 5.5.6+dfsg-2
Date: Thu, 12 Dec 2013 10:50:33 +0000
Source: php5
Source-Version: 5.5.6+dfsg-2

We believe that the bug you reported is fixed in the latest version of
php5, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 731895@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ondřej Surý <ondrej@debian.org> (supplier of updated php5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 12 Dec 2013 11:07:11 +0100
Source: php5
Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm libphp5-embed php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-imap php5-interbase php5-intl php5-ldap php5-mcrypt php5-readline php5-mysql php5-mysqlnd php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl
Architecture: source all amd64
Version: 5.5.6+dfsg-2
Distribution: unstable
Urgency: high
Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>
Changed-By: Ondřej Surý <ondrej@debian.org>
Description: 
 libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module)
 libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo
 libphp5-embed - HTML-embedded scripting language (Embedded SAPI library)
 php-pear   - PEAR - PHP Extension and Application Repository
 php5       - server-side, HTML-embedded scripting language (metapackage)
 php5-cgi   - server-side, HTML-embedded scripting language (CGI binary)
 php5-cli   - command-line interpreter for the php5 scripting language
 php5-common - Common files for packages built from the php5 source
 php5-curl  - CURL module for php5
 php5-dbg   - Debug symbols for PHP5
 php5-dev   - Files for PHP5 module development
 php5-enchant - Enchant module for php5
 php5-fpm   - server-side, HTML-embedded scripting language (FPM-CGI binary)
 php5-gd    - GD module for php5
 php5-gmp   - GMP module for php5
 php5-imap  - IMAP module for php5
 php5-interbase - interbase/firebird module for php5
 php5-intl  - internationalisation module for php5
 php5-ldap  - LDAP module for php5
 php5-mcrypt - MCrypt module for php5
 php5-mysql - MySQL module for php5
 php5-mysqlnd - MySQL module for php5 (Native Driver)
 php5-odbc  - ODBC module for php5
 php5-pgsql - PostgreSQL module for php5
 php5-pspell - pspell module for php5
 php5-readline - Readline module for php5
 php5-recode - recode module for php5
 php5-snmp  - SNMP module for php5
 php5-sqlite - SQLite module for php5
 php5-sybase - Sybase / MS SQL Server module for php5
 php5-tidy  - tidy module for php5
 php5-xmlrpc - XML-RPC module for php5
 php5-xsl   - XSL module for php5
Closes: 731112 731895 731698
Changes: 
 php5 (5.5.6+dfsg-2) unstable; urgency=high
 .
   * [CVE-2013-6420]: Fix memory corruption in openssl_x509_parse (Closes: #731895)
   * [CVE-2013-6712] Fix heap buffer over-read in DateInterval (Closes: #731112)
   * Add patch to fix freetype2 include directory (Closes: #731698)
Checksums-Sha1: 
 a078b7a256c7f808cde24b5e0822ecca05ce5c2c 3937 php5_5.5.6+dfsg-2.dsc
 2cf4431227dbe3f64349f182421ddaccc5180f45 137521 php5_5.5.6+dfsg-2.debian.tar.gz
 0a2b6c0f007cad63d4d4b8cd1ff1e6d1e0939bb7 1256 php5_5.5.6+dfsg-2_all.deb
 9bddfbd0b6b1ee680d5bbec2e1cad4ed9340cd3e 266874 php-pear_5.5.6+dfsg-2_all.deb
 ed45bca39a76babb81f56d7992ddcefdecccddd3 352170 php5-common_5.5.6+dfsg-2_amd64.deb
 99a489a28265d60471fb5809a74a64dcf8b0add1 2131768 libapache2-mod-php5_5.5.6+dfsg-2_amd64.deb
 11bba93679be8169f353f73ac25868e4601c7e8b 2137596 libapache2-mod-php5filter_5.5.6+dfsg-2_amd64.deb
 e8bdff9f9cea910395e06a3289d94cfe23c66d3e 4107548 php5-cgi_5.5.6+dfsg-2_amd64.deb
 50a48a6f644f69d10a885c373acf9a6f5fea57a0 2090256 php5-cli_5.5.6+dfsg-2_amd64.deb
 c13244e2f0eaea04c524a8febaf293a6a6777d13 2107996 php5-fpm_5.5.6+dfsg-2_amd64.deb
 3685964cf929c801e317adcfc61bbd13d02a0cbc 2133294 libphp5-embed_5.5.6+dfsg-2_amd64.deb
 c21eeec038d586efcda227bc1ef157515292aca1 348648 php5-dev_5.5.6+dfsg-2_amd64.deb
 83ae15203f6903e083824ee428601a6d6912f140 30274104 php5-dbg_5.5.6+dfsg-2_amd64.deb
 b349535f57b8c65afedb5da451129ee96142aa5f 26956 php5-curl_5.5.6+dfsg-2_amd64.deb
 7b705c45ff4385f949bcae37e057cfab56f5a487 9066 php5-enchant_5.5.6+dfsg-2_amd64.deb
 755c2f2ae966663813c11eb4ff31f55de341192a 27524 php5-gd_5.5.6+dfsg-2_amd64.deb
 f002e657a2476f67f3c16bdfa2e2b1e180e9d945 14640 php5-gmp_5.5.6+dfsg-2_amd64.deb
 f51c09ec2700225b7c2323d5b2f1c2396529ca70 29986 php5-imap_5.5.6+dfsg-2_amd64.deb
 778138f825a8ef9dfe1afd5cf7f2a67bbc4660ff 41306 php5-interbase_5.5.6+dfsg-2_amd64.deb
 768c1d392cd8874924a619ffaabcb243307b39cc 108330 php5-intl_5.5.6+dfsg-2_amd64.deb
 7749217295a3412a155b0177ce5cbc8764f5fa6e 18950 php5-ldap_5.5.6+dfsg-2_amd64.deb
 be99c2bc64a354237591abfecaca6150afad2e4f 13992 php5-mcrypt_5.5.6+dfsg-2_amd64.deb
 9929f7eaa7364b711514b77357cb98cd252cc3cc 12060 php5-readline_5.5.6+dfsg-2_amd64.deb
 02a182645f190e354f3921e55b377999799781da 62854 php5-mysql_5.5.6+dfsg-2_amd64.deb
 32d6d3c4ef23a83d8bb4e55333e4577a7788dc66 134660 php5-mysqlnd_5.5.6+dfsg-2_amd64.deb
 7e54761a8ba27715f8c98f67470303c0183758c1 30194 php5-odbc_5.5.6+dfsg-2_amd64.deb
 7ac4d2b41ab89ce1d697cd2734d077b1eee3f39d 51382 php5-pgsql_5.5.6+dfsg-2_amd64.deb
 d3dfcb32ae6ba9b1321893fd776bdbfaab8d4d6b 8030 php5-pspell_5.5.6+dfsg-2_amd64.deb
 53d367cfc7a96962270d3ebfe54de9b5937bd992 5376 php5-recode_5.5.6+dfsg-2_amd64.deb
 77899ddfd418d8702b2d65b37ce1a3a93a7cc1c1 19060 php5-snmp_5.5.6+dfsg-2_amd64.deb
 01c70f1c95f5735162848e6d78e7914f36af7822 24032 php5-sqlite_5.5.6+dfsg-2_amd64.deb
 62036aa23902387377ffb2b831296c9e5d6a056b 23826 php5-sybase_5.5.6+dfsg-2_amd64.deb
 089c77fe82164ef791d19901765a873f41fd1df5 16118 php5-tidy_5.5.6+dfsg-2_amd64.deb
 e4aff358b6ede49530474e6cfa9ce188b5299c2d 34916 php5-xmlrpc_5.5.6+dfsg-2_amd64.deb
 a2718385621f42446154ed3684c4a8409d4a9964 13674 php5-xsl_5.5.6+dfsg-2_amd64.deb
Checksums-Sha256: 
 2d9bf8e3ccf8aefaaac605b1bfe423a16fc9795891c0dfbfc49bd60a93a71869 3937 php5_5.5.6+dfsg-2.dsc
 ea6d02a0d5820bd80caf25c7b8161d257d662b9708376da9d2c96d974fe6e1a4 137521 php5_5.5.6+dfsg-2.debian.tar.gz
 a5ca1742b5b7a2f78f6cf104b978b52ea29215972f0a838a87706183679f7fa2 1256 php5_5.5.6+dfsg-2_all.deb
 5868572e4496d120efed3914cc9bc1a106a6cc475e1f1e8fff06bff1007e97ba 266874 php-pear_5.5.6+dfsg-2_all.deb
 5d899e112f021e0db15b22679aed80423de9555642e2ee78d108023f473f4486 352170 php5-common_5.5.6+dfsg-2_amd64.deb
 ca54e398c17c2a6c1b23769b1ec0e16af458b8f9996c4ec1d7cb8fef46c197a4 2131768 libapache2-mod-php5_5.5.6+dfsg-2_amd64.deb
 013786caa3c6aa43a4a6e2289547c77b5579673289bdb5494f93f6ec9cd08200 2137596 libapache2-mod-php5filter_5.5.6+dfsg-2_amd64.deb
 7a7d0d206ee5447572de7bbffadac3bfe0d64e83a062d5407770e4436abeb760 4107548 php5-cgi_5.5.6+dfsg-2_amd64.deb
 39f4d880bf4226c4d819695c00971b241d270e50a1ebe9c056ec8d4a65b99c0f 2090256 php5-cli_5.5.6+dfsg-2_amd64.deb
 8e1a988bf666dd4d4da26069de21558b608d846a6f78df3fe97e0c4d614ca7f7 2107996 php5-fpm_5.5.6+dfsg-2_amd64.deb
 35f8c3af87455e9724aa445b0a3f13e3706276d4b701b934851d321ae14f60ee 2133294 libphp5-embed_5.5.6+dfsg-2_amd64.deb
 173fd5fde363a0165475aeb723868156787d71b90b6b035e692566b8f1866ef4 348648 php5-dev_5.5.6+dfsg-2_amd64.deb
 14df06f7b13502451ebd525f83a611389fca134f22085ba8cdab002bec9cd36e 30274104 php5-dbg_5.5.6+dfsg-2_amd64.deb
 22511c2b3224ad64b39a66bda05622bb1ec9511eb81c3390d1a49f54cfed26fc 26956 php5-curl_5.5.6+dfsg-2_amd64.deb
 a1f0168de07fabf46b56ecc5b3b1a69fd8fd7ff001b7a06c3d8f7e9da06b5066 9066 php5-enchant_5.5.6+dfsg-2_amd64.deb
 0c68a4eea11363ca15ad50b2d28839472abffb7b33d3a04d59086f45de0785f5 27524 php5-gd_5.5.6+dfsg-2_amd64.deb
 a83060d6b51d8135626e549bd38c0c14f5979c6ca12b6490d0a10eef1c0cb399 14640 php5-gmp_5.5.6+dfsg-2_amd64.deb
 dc7da85344153141537f9ce93ffc5fca02e4ab58e30fbb74d2e5bc9c8aa9f0f0 29986 php5-imap_5.5.6+dfsg-2_amd64.deb
 ac43974f4451ca1d948ef61057b1f912b922a56a9267f5a426f7fd443134132b 41306 php5-interbase_5.5.6+dfsg-2_amd64.deb
 48b1a308919ee68048fe2d97756ffc925491dcec036cd112e4f4e532b750998f 108330 php5-intl_5.5.6+dfsg-2_amd64.deb
 4fdf1f597510bb8a3a6b36f55fcd0549268ca39faec98e590ce364e1b5fcf032 18950 php5-ldap_5.5.6+dfsg-2_amd64.deb
 72c54a909e3a0c19253481277ace48e2ef63cc796a6453bb09c4a91f29beb3cb 13992 php5-mcrypt_5.5.6+dfsg-2_amd64.deb
 fbb1d38a80637062b54373c9961a842cea1abef5169eaf0feb87faf708c4dbe3 12060 php5-readline_5.5.6+dfsg-2_amd64.deb
 396e6b725cab388c37eb5eec5444ec538ac19dd95613f65c7e10285615c95bae 62854 php5-mysql_5.5.6+dfsg-2_amd64.deb
 611bb771dfe544f67e4aff72c61079b2347e582c49ac7e056c26abee0b0a6c40 134660 php5-mysqlnd_5.5.6+dfsg-2_amd64.deb
 418ebcdfad2d324b94f9fa0728e624ebca89e2255d752387aac9a4e962f4f83a 30194 php5-odbc_5.5.6+dfsg-2_amd64.deb
 59f0625fc46cd6b08d0b665c2e80655cafdd7d117b0fc56297427608e6377892 51382 php5-pgsql_5.5.6+dfsg-2_amd64.deb
 5fe411e81f68d31a55a8cb3a525bcfaf1c7aa11b0cc7f244f44c1f53d27c45ee 8030 php5-pspell_5.5.6+dfsg-2_amd64.deb
 c4728b791dde65934364d5e4e390e5164c287d0ef3a1c2e3a01eef4f35362b33 5376 php5-recode_5.5.6+dfsg-2_amd64.deb
 6b80c54ae48f0cf8d8d762c9d4f5e75468712302b555211501a9e678a9a98c1a 19060 php5-snmp_5.5.6+dfsg-2_amd64.deb
 624ae8542912a070aecec43b3265f72f2c5065c11fbedbdf44237e595acc45f1 24032 php5-sqlite_5.5.6+dfsg-2_amd64.deb
 8eb15c79723bd7ada81477163e15372b3f8423042813ffd3beffe2c2dad746f4 23826 php5-sybase_5.5.6+dfsg-2_amd64.deb
 b39c7ca2b9e8e20fbaf435e8fd5f35646a99f030c764c68846f5b966bd838df4 16118 php5-tidy_5.5.6+dfsg-2_amd64.deb
 9ea8eccac2310081d582265838f589f1afd075e78f797c05f2ca983c17e277cb 34916 php5-xmlrpc_5.5.6+dfsg-2_amd64.deb
 2d355d0912443fb616a9e283cdb1317cb73a5af47f11fd90e82e32ea694aa566 13674 php5-xsl_5.5.6+dfsg-2_amd64.deb
Files: 
 0965b6507ab77f069ad860c9ec4adf7c 3937 php optional php5_5.5.6+dfsg-2.dsc
 88be9a7ef46513de77c3bb9c838e6c28 137521 php optional php5_5.5.6+dfsg-2.debian.tar.gz
 74a2c8ba019d3a22b289e899cdad7fab 1256 php optional php5_5.5.6+dfsg-2_all.deb
 723f142b12eee4fb417da86a701c7c47 266874 php optional php-pear_5.5.6+dfsg-2_all.deb
 75927fbe13afe0d00942981e43f874d1 352170 php optional php5-common_5.5.6+dfsg-2_amd64.deb
 7b895bfe008808f5353edef04b927b36 2131768 httpd optional libapache2-mod-php5_5.5.6+dfsg-2_amd64.deb
 83952c1801f1cbdfb89cc725aa33d5e2 2137596 httpd extra libapache2-mod-php5filter_5.5.6+dfsg-2_amd64.deb
 9c79e61a69c8e089fdff57fcab5871a7 4107548 php optional php5-cgi_5.5.6+dfsg-2_amd64.deb
 7a2b2e42ff3f1c540d058e9195dd2502 2090256 php optional php5-cli_5.5.6+dfsg-2_amd64.deb
 a41ac859da93ebe254daa470b07e1fef 2107996 php optional php5-fpm_5.5.6+dfsg-2_amd64.deb
 5c9b086b29cb5a70dd35939813914bf7 2133294 php optional libphp5-embed_5.5.6+dfsg-2_amd64.deb
 144623e2328735455b899f8cf5041205 348648 php optional php5-dev_5.5.6+dfsg-2_amd64.deb
 11a37a100afca75c07e0a3d986376075 30274104 debug extra php5-dbg_5.5.6+dfsg-2_amd64.deb
 03df0cc41d19cf9b29f03de19d72b954 26956 php optional php5-curl_5.5.6+dfsg-2_amd64.deb
 fb1b1d1d21c274c121b6d2ba013fbab8 9066 php optional php5-enchant_5.5.6+dfsg-2_amd64.deb
 3cc346080637dac9b0249b16e24d67ff 27524 php optional php5-gd_5.5.6+dfsg-2_amd64.deb
 7c14d8fa7ac554fcd470c1ff01c9da8b 14640 php optional php5-gmp_5.5.6+dfsg-2_amd64.deb
 1f436abfe0b86d151a4d762840d3833c 29986 php optional php5-imap_5.5.6+dfsg-2_amd64.deb
 12ce31d34dc9568074f92d263eef6444 41306 php optional php5-interbase_5.5.6+dfsg-2_amd64.deb
 ff5d5ab6f98f4775d2ec996cf62d60a8 108330 php optional php5-intl_5.5.6+dfsg-2_amd64.deb
 b6d02bb836a00136d1d9f6f8c71f89bc 18950 php optional php5-ldap_5.5.6+dfsg-2_amd64.deb
 61f2c2a3c4b190734bb001e81fa56c5f 13992 php optional php5-mcrypt_5.5.6+dfsg-2_amd64.deb
 64c099450008ebba9eb48c878d68fe0c 12060 php optional php5-readline_5.5.6+dfsg-2_amd64.deb
 c70af0e1dda9955f6a3192dd0865a82c 62854 php optional php5-mysql_5.5.6+dfsg-2_amd64.deb
 3c96a99354b518a2e8a5181d8eaa51ed 134660 php extra php5-mysqlnd_5.5.6+dfsg-2_amd64.deb
 e9a69f6eb225b6c0b7f6b8779cb8ed4d 30194 php optional php5-odbc_5.5.6+dfsg-2_amd64.deb
 4d37b3c5c75756be5ddffae420288daa 51382 php optional php5-pgsql_5.5.6+dfsg-2_amd64.deb
 0046657d27bb6293327dfdf127870a89 8030 php optional php5-pspell_5.5.6+dfsg-2_amd64.deb
 1f2679b2603dfb88d826971d50596da0 5376 php optional php5-recode_5.5.6+dfsg-2_amd64.deb
 47492379fc3b2f2c37fb3fcbde514c3f 19060 php optional php5-snmp_5.5.6+dfsg-2_amd64.deb
 397627092022b8cc60a1960407355837 24032 php optional php5-sqlite_5.5.6+dfsg-2_amd64.deb
 b1851ec48eb681e90086da2c24105dd7 23826 php optional php5-sybase_5.5.6+dfsg-2_amd64.deb
 a5bf7341b9a5cd6c2fb4d4b43380dec6 16118 php optional php5-tidy_5.5.6+dfsg-2_amd64.deb
 2c8c2bc07bddb5399c01a6e869489f64 34916 php optional php5-xmlrpc_5.5.6+dfsg-2_amd64.deb
 71449c7b24ec555bc02728850cef61af 13674 php optional php5-xsl_5.5.6+dfsg-2_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlKpkL8ACgkQ9OZqfMIN8nOG3wCgh9Mvu+psLeCcvAIo5gHO50zM
SCQAoKZH0uZaWb1vvh01906RfaWk0M/+
=pti8
-----END PGP SIGNATURE-----




Reply sent to Ondřej Surý <ondrej@debian.org>:
You have taken responsibility. (Thu, 12 Dec 2013 21:24:40 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Thu, 12 Dec 2013 21:24:40 GMT) (full text, mbox, link).


Message #20 received at 731895-close@bugs.debian.org (full text, mbox, reply):

From: Ondřej Surý <ondrej@debian.org>
To: 731895-close@bugs.debian.org
Subject: Bug#731895: fixed in php5 5.5.7+dfsg-1
Date: Thu, 12 Dec 2013 21:22:42 +0000
Source: php5
Source-Version: 5.5.7+dfsg-1

We believe that the bug you reported is fixed in the latest version of
php5, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 731895@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ondřej Surý <ondrej@debian.org> (supplier of updated php5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 12 Dec 2013 20:49:21 +0100
Source: php5
Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm libphp5-embed php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-imap php5-interbase php5-intl php5-ldap php5-mcrypt php5-readline php5-mysql php5-mysqlnd php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl
Architecture: source all amd64
Version: 5.5.7+dfsg-1
Distribution: unstable
Urgency: high
Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>
Changed-By: Ondřej Surý <ondrej@debian.org>
Description: 
 libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module)
 libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo
 libphp5-embed - HTML-embedded scripting language (Embedded SAPI library)
 php-pear   - PEAR - PHP Extension and Application Repository
 php5       - server-side, HTML-embedded scripting language (metapackage)
 php5-cgi   - server-side, HTML-embedded scripting language (CGI binary)
 php5-cli   - command-line interpreter for the php5 scripting language
 php5-common - Common files for packages built from the php5 source
 php5-curl  - CURL module for php5
 php5-dbg   - Debug symbols for PHP5
 php5-dev   - Files for PHP5 module development
 php5-enchant - Enchant module for php5
 php5-fpm   - server-side, HTML-embedded scripting language (FPM-CGI binary)
 php5-gd    - GD module for php5
 php5-gmp   - GMP module for php5
 php5-imap  - IMAP module for php5
 php5-interbase - interbase/firebird module for php5
 php5-intl  - internationalisation module for php5
 php5-ldap  - LDAP module for php5
 php5-mcrypt - MCrypt module for php5
 php5-mysql - MySQL module for php5
 php5-mysqlnd - MySQL module for php5 (Native Driver)
 php5-odbc  - ODBC module for php5
 php5-pgsql - PostgreSQL module for php5
 php5-pspell - pspell module for php5
 php5-readline - Readline module for php5
 php5-recode - recode module for php5
 php5-snmp  - SNMP module for php5
 php5-sqlite - SQLite module for php5
 php5-sybase - Sybase / MS SQL Server module for php5
 php5-tidy  - tidy module for php5
 php5-xmlrpc - XML-RPC module for php5
 php5-xsl   - XSL module for php5
Closes: 730528 731895
Changes: 
 php5 (5.5.7+dfsg-1) unstable; urgency=high
 .
   * New upstream version 5.5.7+dfsg
    + [CVE-2013-6420]: Fix memory corruption in openssl_x509_parse (Closes: #731895)
   * Enable dtrace/systemtap support (Closes: #730528)
Checksums-Sha1: 
 45561571b9aa70e6872ec5e489a0de278c8b95f0 3956 php5_5.5.7+dfsg-1.dsc
 6eb0fe206336e03740a6c7d7c72dd2c7fd28c9b4 10823400 php5_5.5.7+dfsg.orig.tar.xz
 74fdb2ec17239db3d463ef315af7db4c9d7f4390 135646 php5_5.5.7+dfsg-1.debian.tar.gz
 ccff0c238cba36dba881e489e7ddb4e301c3ffb3 1254 php5_5.5.7+dfsg-1_all.deb
 aedeee3c025b46f69656355451c0938b27179168 266898 php-pear_5.5.7+dfsg-1_all.deb
 2e3d01cc35fa8fd7ac274de0630614a9097afe3c 352862 php5-common_5.5.7+dfsg-1_amd64.deb
 1cf18373b9c48920176e15e67b2d7bb12e1bad3a 2137580 libapache2-mod-php5_5.5.7+dfsg-1_amd64.deb
 e823b0d7cfe8f6ebf2725148a1a97fef2c579c2f 2136906 libapache2-mod-php5filter_5.5.7+dfsg-1_amd64.deb
 71d78369cdef36c8b73462773be01a1ffe0aba8a 4105944 php5-cgi_5.5.7+dfsg-1_amd64.deb
 1f1feebf4f65c7d0682966839a88b1ddea7ffb0e 2090410 php5-cli_5.5.7+dfsg-1_amd64.deb
 aacd07e3d6f2255fb1f4b5298fc259e54eed224b 2116214 php5-fpm_5.5.7+dfsg-1_amd64.deb
 c87419a96b760d99967fecfba588847dbbcace45 2134202 libphp5-embed_5.5.7+dfsg-1_amd64.deb
 fcc413c018c72e0664d0b38ccd6bd3cb662b45cf 349644 php5-dev_5.5.7+dfsg-1_amd64.deb
 09b06a47ed528c5bf4e3592fce9d50e7d04d553e 30295604 php5-dbg_5.5.7+dfsg-1_amd64.deb
 55d48341af768c0838357843e30289d2a95bdd66 27034 php5-curl_5.5.7+dfsg-1_amd64.deb
 db8a4c3f20cadcee0de0c0979433a2598289c14e 9068 php5-enchant_5.5.7+dfsg-1_amd64.deb
 3f54d2cff82a433655d2227d95820bc484110ae4 27430 php5-gd_5.5.7+dfsg-1_amd64.deb
 8915740699649e9db12108de442dcd1c08184a17 14624 php5-gmp_5.5.7+dfsg-1_amd64.deb
 50a9f7cb1ba3d5316f3585154311605e205e08b2 30014 php5-imap_5.5.7+dfsg-1_amd64.deb
 5135513e4e777deca1cae5c1eb84d1c20c1c0f7a 41398 php5-interbase_5.5.7+dfsg-1_amd64.deb
 c64a6844502a55d7dddfcc4b5e84f00894edd230 108566 php5-intl_5.5.7+dfsg-1_amd64.deb
 13b620ff565b869599227b147132565a11e43b13 18906 php5-ldap_5.5.7+dfsg-1_amd64.deb
 95d7fb60094d96fb5d8dcf9aa71e0ed1bfb302d7 13998 php5-mcrypt_5.5.7+dfsg-1_amd64.deb
 c1f43c53a71709c60779ec3dcc25e3b676fa23de 11980 php5-readline_5.5.7+dfsg-1_amd64.deb
 8455bd07cd5ff83f3aa594928149bdda4e61136d 62838 php5-mysql_5.5.7+dfsg-1_amd64.deb
 31483c339469e42f9551b8ec22ced7865bb9d145 134724 php5-mysqlnd_5.5.7+dfsg-1_amd64.deb
 853acfb63695ad3ab8b9f6fed11e33148737db9a 30180 php5-odbc_5.5.7+dfsg-1_amd64.deb
 5cb742657ea285fdf7c44bd1f8b8bab2f4dba23a 51448 php5-pgsql_5.5.7+dfsg-1_amd64.deb
 3baf215d4a047120669e664d620b7266c6b5b0d0 8016 php5-pspell_5.5.7+dfsg-1_amd64.deb
 d99d14b0177527f559461c56786d59fb98049f42 5388 php5-recode_5.5.7+dfsg-1_amd64.deb
 d8a5b227f67fc6a1f4a7ca968003531b702a0fc8 19058 php5-snmp_5.5.7+dfsg-1_amd64.deb
 d18e75b4646f9424c27fc079abf994e687fb4260 24042 php5-sqlite_5.5.7+dfsg-1_amd64.deb
 72a7a82eee23c52d5b0bc0a9241cc92f8189ed71 23822 php5-sybase_5.5.7+dfsg-1_amd64.deb
 83128c5f5890e7063916e47d225ed3aae835f3d2 16112 php5-tidy_5.5.7+dfsg-1_amd64.deb
 d1824ce97a39d64f802f134a6522768acf57372d 35018 php5-xmlrpc_5.5.7+dfsg-1_amd64.deb
 273d5e8ebac1b8c3ec383bf7033dcf928140ae45 13734 php5-xsl_5.5.7+dfsg-1_amd64.deb
Checksums-Sha256: 
 c1154c5b1f84624b00ad27b2a9c270535e7aa33203257a14c69b66b50c5a0797 3956 php5_5.5.7+dfsg-1.dsc
 39f1fb9042950307e58b8e1ec300a636c7fee6117ef00bc2ea8751920e44ab3a 10823400 php5_5.5.7+dfsg.orig.tar.xz
 895eaf53abdc7d880d5be0f2ba0914210b979014de007a9b7d8e3bcc3c55686c 135646 php5_5.5.7+dfsg-1.debian.tar.gz
 7d23c7178b4dbbee0f1616df0c7d7dda694476f70333821c3b2fc5d4f01a23b1 1254 php5_5.5.7+dfsg-1_all.deb
 4d3fa954d131b994269fc15b58e2819abdb4f035370e2da785d4a589a4c1e63c 266898 php-pear_5.5.7+dfsg-1_all.deb
 363bb95f53acaa38e182f8a2a9ac28021211e5ea5e45c860f31bc1f725fa07af 352862 php5-common_5.5.7+dfsg-1_amd64.deb
 8bfbd34680636962c801897e8a0d58471972fd09f851be19f34fcce8d662a15a 2137580 libapache2-mod-php5_5.5.7+dfsg-1_amd64.deb
 edeefe2f3843a06683baa3a45b0c74ac70293013a983b76f9ac3ea746b156c3a 2136906 libapache2-mod-php5filter_5.5.7+dfsg-1_amd64.deb
 95bf3fb97d4c618299cf66d10c1479ce755c73b6a1e0523e9ecca3556b4723eb 4105944 php5-cgi_5.5.7+dfsg-1_amd64.deb
 d56e9bfbd5b699c9c516acb116de468bac7603a377617d6474ccf68833ef5cc6 2090410 php5-cli_5.5.7+dfsg-1_amd64.deb
 eee57386f10715fb18c7c409ca34de199f1e5e9847f49a439bfc7a11738b0feb 2116214 php5-fpm_5.5.7+dfsg-1_amd64.deb
 fe43f2b17d99866532561ea9f3b0e61bdaf869545e115b08a415163883661aab 2134202 libphp5-embed_5.5.7+dfsg-1_amd64.deb
 1677820898e2fb3d2a2a353777eb805d5104884a2b3dcbaff25ea40e5fc15801 349644 php5-dev_5.5.7+dfsg-1_amd64.deb
 e1872e7a99aef90aa1a486f3d072dcfef4c82fc39bfeb583bad87d2ab9c11bf8 30295604 php5-dbg_5.5.7+dfsg-1_amd64.deb
 bd653941cf0fc766bda73e99819b673e2ac04ee6697897c25d0fb925c8f158eb 27034 php5-curl_5.5.7+dfsg-1_amd64.deb
 f93373efa5c99791c752405e6fb08e2c2fccad094ee4c3f51f6f74ef8e113abb 9068 php5-enchant_5.5.7+dfsg-1_amd64.deb
 0f8287033a8e91089b7b757f1aded0702ef797b498f3d86698163f3c928db2e5 27430 php5-gd_5.5.7+dfsg-1_amd64.deb
 bba87eba5ec02afc91ee2ec8bfb2845d2f23af858415e99c94ff9a7ecae939d6 14624 php5-gmp_5.5.7+dfsg-1_amd64.deb
 1bed486f01502b1ec7be9a9381e713c563a562b7ac30fe29d9043f8a37d2a544 30014 php5-imap_5.5.7+dfsg-1_amd64.deb
 72d9bb5fbb22acc4118555dd8bd6d75bab04ad3c16e056f14dd92078ef686932 41398 php5-interbase_5.5.7+dfsg-1_amd64.deb
 1ce6198557e1cad3ddaa0c7aab688bd806a59d9f234576354084c7b0187c1680 108566 php5-intl_5.5.7+dfsg-1_amd64.deb
 d995ea37dda537955c6fb838623d90aae5d64be7d1039d67672744ea2911d816 18906 php5-ldap_5.5.7+dfsg-1_amd64.deb
 272b737479a662791ca784c8eef4cb3a08d153d4244b5949a92f996c38624010 13998 php5-mcrypt_5.5.7+dfsg-1_amd64.deb
 b6bb02e6333470281fd175692cd4d3144a758245bc66df22f7dcd16d4e49c231 11980 php5-readline_5.5.7+dfsg-1_amd64.deb
 a74646476e6ddf1adc1b6125cfc55363d8d50977935f6891827d54e38032c3db 62838 php5-mysql_5.5.7+dfsg-1_amd64.deb
 378e4ed7f6bc0faec6dad875962268646570aaeceaf74aca6c9f685dfbfa58fd 134724 php5-mysqlnd_5.5.7+dfsg-1_amd64.deb
 9a97be4995c5f4f98eb58953bb02c8b538e46b447a5d5d856d3e34141a5259e5 30180 php5-odbc_5.5.7+dfsg-1_amd64.deb
 e2660de798b935a8ad2276024390b7f183eead08ad9ec8ab3dd98d0060e693b6 51448 php5-pgsql_5.5.7+dfsg-1_amd64.deb
 b087f9371a33ae4d6465aa4cd2265d562364e15d471a364763cef1c22127d48f 8016 php5-pspell_5.5.7+dfsg-1_amd64.deb
 3e5627e5362e73bc66d631587eea073b17615b75068a7ce813a784af196ece5e 5388 php5-recode_5.5.7+dfsg-1_amd64.deb
 9368c20282563038838b113fd28649c5f6f22f2c36525282bb0feb4b9d633e5d 19058 php5-snmp_5.5.7+dfsg-1_amd64.deb
 357cc22ecb28de7698c2253d36d949e644c3a5d80ab1baf0d3ce6110c0ffe646 24042 php5-sqlite_5.5.7+dfsg-1_amd64.deb
 b02ec4081183def8e94257fe0a7bc6861f62008564230eb1a87fa9431c79265e 23822 php5-sybase_5.5.7+dfsg-1_amd64.deb
 e17a641ccaa26b8e1942617760dc73f10d9014222fdbfc3d5333911aadea242a 16112 php5-tidy_5.5.7+dfsg-1_amd64.deb
 05c844f475c28b865f666b50d9743c12446c12ba82bbfd1eec0b5e80ef4b2f0e 35018 php5-xmlrpc_5.5.7+dfsg-1_amd64.deb
 f9a75f6282c57e28897caae105b936ae70b5b4a047f3136ff20fcacebbacdd8a 13734 php5-xsl_5.5.7+dfsg-1_amd64.deb
Files: 
 15e2546d9abb13128abaee545d8c008a 3956 php optional php5_5.5.7+dfsg-1.dsc
 77af51aea5a078bd34a1ccd55297d98a 10823400 php optional php5_5.5.7+dfsg.orig.tar.xz
 c5ad4c4b128652734534ed1d76a033be 135646 php optional php5_5.5.7+dfsg-1.debian.tar.gz
 0d8853b0adf2933e9a18aff0136a44ae 1254 php optional php5_5.5.7+dfsg-1_all.deb
 1a7b5923d5b85abb2f0e40b32b9b3e21 266898 php optional php-pear_5.5.7+dfsg-1_all.deb
 5c591994bb1911d045720ef7c338ea9d 352862 php optional php5-common_5.5.7+dfsg-1_amd64.deb
 5cb41865ca5a040f6b6fd4d712fc5cd6 2137580 httpd optional libapache2-mod-php5_5.5.7+dfsg-1_amd64.deb
 94c04c1d5859bf047f183d6ac1e24fd5 2136906 httpd extra libapache2-mod-php5filter_5.5.7+dfsg-1_amd64.deb
 a3dd1b05febccfa3146dea0326a1e798 4105944 php optional php5-cgi_5.5.7+dfsg-1_amd64.deb
 e42e8fcfe4de19ff11106745437c92fd 2090410 php optional php5-cli_5.5.7+dfsg-1_amd64.deb
 8ff7d986fe83743ae5ab4a7c6ce1ad47 2116214 php optional php5-fpm_5.5.7+dfsg-1_amd64.deb
 785000284d0c48beaaa6927e29df767b 2134202 php optional libphp5-embed_5.5.7+dfsg-1_amd64.deb
 3f7d66cb959c39950d039320243b4d57 349644 php optional php5-dev_5.5.7+dfsg-1_amd64.deb
 599f8d4b2a0da3af200a2577666c3cf0 30295604 debug extra php5-dbg_5.5.7+dfsg-1_amd64.deb
 109ad4f3ea3bfe0c500b0075f5424efe 27034 php optional php5-curl_5.5.7+dfsg-1_amd64.deb
 a1815f0187ea1bbb42a219dbab107011 9068 php optional php5-enchant_5.5.7+dfsg-1_amd64.deb
 726dc42e715b4e279532fedf97b37bde 27430 php optional php5-gd_5.5.7+dfsg-1_amd64.deb
 2a94a84971b57dd0decd9893edd525d1 14624 php optional php5-gmp_5.5.7+dfsg-1_amd64.deb
 b455452bab05314804ff4a383223ac6b 30014 php optional php5-imap_5.5.7+dfsg-1_amd64.deb
 8d44371419a0bd79230b1bacde937e37 41398 php optional php5-interbase_5.5.7+dfsg-1_amd64.deb
 9c72ab839eab243b384f6b65506276fc 108566 php optional php5-intl_5.5.7+dfsg-1_amd64.deb
 d2c51f04df57c8fc19c028e82c810d58 18906 php optional php5-ldap_5.5.7+dfsg-1_amd64.deb
 7645112ae3d966f10798c9c7be7f930f 13998 php optional php5-mcrypt_5.5.7+dfsg-1_amd64.deb
 f19af1eb11b8ccd328b8d7c9a1078e4c 11980 php optional php5-readline_5.5.7+dfsg-1_amd64.deb
 27a69b2f03e4d0de5b78b2266388585b 62838 php optional php5-mysql_5.5.7+dfsg-1_amd64.deb
 4d91d7dcd579fd14399381db83c3c078 134724 php extra php5-mysqlnd_5.5.7+dfsg-1_amd64.deb
 29c32386e574b66c96cbd2a3aa286af3 30180 php optional php5-odbc_5.5.7+dfsg-1_amd64.deb
 176a1f1d0a579eb0f39bf136fba92264 51448 php optional php5-pgsql_5.5.7+dfsg-1_amd64.deb
 069e1b7d77e793d335454d6478a561e1 8016 php optional php5-pspell_5.5.7+dfsg-1_amd64.deb
 598454bf551b8b9c53c42a1ff6501464 5388 php optional php5-recode_5.5.7+dfsg-1_amd64.deb
 fdf34c30bc0556cb8683905239b64a8f 19058 php optional php5-snmp_5.5.7+dfsg-1_amd64.deb
 53fb3ec09be1aa9b0d5674d0f46b8019 24042 php optional php5-sqlite_5.5.7+dfsg-1_amd64.deb
 ce821527bbc4ed938fb6793c07e4c1c3 23822 php optional php5-sybase_5.5.7+dfsg-1_amd64.deb
 1de799d8bae88ffa4a8167aff459e285 16112 php optional php5-tidy_5.5.7+dfsg-1_amd64.deb
 b6ad1bbc3e5b34d3f1f4ce63d29c02f6 35018 php optional php5-xmlrpc_5.5.7+dfsg-1_amd64.deb
 2477957caf0d8a2d592ba4913e0549e4 13734 php optional php5-xsl_5.5.7+dfsg-1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlKqHqMACgkQ9OZqfMIN8nPGiQCgizsjCeevJDU4ZDDJfXdruMWE
FzoAoIV+gpZ7jKsaZVytME8sDPGKXUR7
=tRZj
-----END PGP SIGNATURE-----




Marked as found in versions php5/5.4.4-14+deb7u5. Request was from Ondřej Surý <ondrej@debian.org> to control@bugs.debian.org. (Thu, 12 Dec 2013 23:00:04 GMT) (full text, mbox, link).


Marked as fixed in versions php5/5.4.4-14+deb7u7. Request was from Ondřej Surý <ondrej@debian.org> to control@bugs.debian.org. (Thu, 12 Dec 2013 23:00:07 GMT) (full text, mbox, link).


Marked as found in versions php5/5.3.3-7+squeeze17. Request was from Ondřej Surý <ondrej@debian.org> to control@bugs.debian.org. (Thu, 12 Dec 2013 23:00:11 GMT) (full text, mbox, link).


Marked as fixed in versions php5/5.3.3-7+squeeze18. Request was from Ondřej Surý <ondrej@debian.org> to control@bugs.debian.org. (Thu, 12 Dec 2013 23:00:13 GMT) (full text, mbox, link).


Reply sent to Ondřej Surý <ondrej@debian.org>:
You have taken responsibility. (Sat, 14 Dec 2013 12:51:19 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sat, 14 Dec 2013 12:51:19 GMT) (full text, mbox, link).


Message #33 received at 731895-close@bugs.debian.org (full text, mbox, reply):

From: Ondřej Surý <ondrej@debian.org>
To: 731895-close@bugs.debian.org
Subject: Bug#731895: fixed in php5 5.4.4-14+deb7u7
Date: Sat, 14 Dec 2013 12:47:35 +0000
Source: php5
Source-Version: 5.4.4-14+deb7u7

We believe that the bug you reported is fixed in the latest version of
php5, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 731895@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ondřej Surý <ondrej@debian.org> (supplier of updated php5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 12 Dec 2013 09:28:14 +0100
Source: php5
Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm libphp5-embed php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-imap php5-interbase php5-intl php5-ldap php5-mcrypt php5-mysql php5-mysqlnd php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl
Architecture: source all amd64
Version: 5.4.4-14+deb7u7
Distribution: wheezy-security
Urgency: low
Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>
Changed-By: Ondřej Surý <ondrej@debian.org>
Description: 
 libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module)
 libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo
 libphp5-embed - HTML-embedded scripting language (Embedded SAPI library)
 php-pear   - PEAR - PHP Extension and Application Repository
 php5       - server-side, HTML-embedded scripting language (metapackage)
 php5-cgi   - server-side, HTML-embedded scripting language (CGI binary)
 php5-cli   - command-line interpreter for the php5 scripting language
 php5-common - Common files for packages built from the php5 source
 php5-curl  - CURL module for php5
 php5-dbg   - Debug symbols for PHP5
 php5-dev   - Files for PHP5 module development
 php5-enchant - Enchant module for php5
 php5-fpm   - server-side, HTML-embedded scripting language (FPM-CGI binary)
 php5-gd    - GD module for php5
 php5-gmp   - GMP module for php5
 php5-imap  - IMAP module for php5
 php5-interbase - interbase/firebird module for php5
 php5-intl  - internationalisation module for php5
 php5-ldap  - LDAP module for php5
 php5-mcrypt - MCrypt module for php5
 php5-mysql - MySQL module for php5
 php5-mysqlnd - MySQL module for php5 (Native Driver)
 php5-odbc  - ODBC module for php5
 php5-pgsql - PostgreSQL module for php5
 php5-pspell - pspell module for php5
 php5-recode - recode module for php5
 php5-snmp  - SNMP module for php5
 php5-sqlite - SQLite module for php5
 php5-sybase - Sybase / MS SQL Server module for php5
 php5-tidy  - tidy module for php5
 php5-xmlrpc - XML-RPC module for php5
 php5-xsl   - XSL module for php5
Closes: 731112 731895
Changes: 
 php5 (5.4.4-14+deb7u7) wheezy-security; urgency=low
 .
   * [CVE-2013-6420]: Fix memory corruption in openssl_x509_parse (Closes: #731895)
   * [CVE-2013-6712] Fix heap buffer over-read in DateInterval (Closes: #731112)
Checksums-Sha1: 
 db945bf5566c133e9a5a8ad8d957477558db1217 3774 php5_5.4.4-14+deb7u7.dsc
 2d5770884b9d82f96845e6f6f264207b204d781e 224674 php5_5.4.4-14+deb7u7.diff.gz
 adac7fb7e845d983957cf4f68b841a6d3bb4bf81 1026 php5_5.4.4-14+deb7u7_all.deb
 f8cb4713a7f6fbeac634351d648784c8b550c346 369272 php-pear_5.4.4-14+deb7u7_all.deb
 7b8f7fee147a6adfc5859ec8a394d740546af1f5 588224 php5-common_5.4.4-14+deb7u7_amd64.deb
 1f19a48535eb3dbdcf1054ea722db264c09825a5 2665644 libapache2-mod-php5_5.4.4-14+deb7u7_amd64.deb
 90c505afee61d55c8ccb5675efd5bda9f10db6a0 2664020 libapache2-mod-php5filter_5.4.4-14+deb7u7_amd64.deb
 33b57b7f454e81225e85c36368f371eae621109c 5100870 php5-cgi_5.4.4-14+deb7u7_amd64.deb
 1a9a04d0a2a2922ed3bdfbbe59eb25595e7ff1cd 2557440 php5-cli_5.4.4-14+deb7u7_amd64.deb
 b1f14068506342c40676e80216d9bd945564dcaa 2590524 php5-fpm_5.4.4-14+deb7u7_amd64.deb
 bf2dc7d66197e8dd4299f156a4bde1a547aadd74 2662062 libphp5-embed_5.4.4-14+deb7u7_amd64.deb
 2fa9c2c45c388052e86de83bc9ee7412aa80b8c9 497438 php5-dev_5.4.4-14+deb7u7_amd64.deb
 1d73dea79699ce71d72dfb1e45e9b690996a897b 15959722 php5-dbg_5.4.4-14+deb7u7_amd64.deb
 aaa2b5540479703de21c4dcfea147a8db43d12d4 29180 php5-curl_5.4.4-14+deb7u7_amd64.deb
 81335f1d8a068ecde1fdedcca93855e95ed5a4a6 9946 php5-enchant_5.4.4-14+deb7u7_amd64.deb
 0bdf85e6fddc81aaf8903b2af6644d2d16d2a75f 35720 php5-gd_5.4.4-14+deb7u7_amd64.deb
 feb35e6db8ef93beebb92ec1f1125ed06cedf5d3 17176 php5-gmp_5.4.4-14+deb7u7_amd64.deb
 16adc4bab5866032694d304cabf008bdafd687db 35614 php5-imap_5.4.4-14+deb7u7_amd64.deb
 bfee5375d0ef1cdc0cfa4f1c71e8fc198b785bb8 49612 php5-interbase_5.4.4-14+deb7u7_amd64.deb
 ec82ca53a7d5d13aace572ce61cf6504f85d608b 71974 php5-intl_5.4.4-14+deb7u7_amd64.deb
 c39ca89875af3f07152fb16cac5963becdd9a330 21774 php5-ldap_5.4.4-14+deb7u7_amd64.deb
 8ac4ea5ea32efd3f085bdb513a14d96708f6b695 16096 php5-mcrypt_5.4.4-14+deb7u7_amd64.deb
 361119a73f99cd21a78986afff7bcd23ad8b88aa 80866 php5-mysql_5.4.4-14+deb7u7_amd64.deb
 ff285289281b7826910243610de159ff3756a612 162732 php5-mysqlnd_5.4.4-14+deb7u7_amd64.deb
 7ad381925371da2b3a428e0ed5cb4f65587e3219 36416 php5-odbc_5.4.4-14+deb7u7_amd64.deb
 68000f4b9410f79129e6653156f9a5eba3e58ae8 61074 php5-pgsql_5.4.4-14+deb7u7_amd64.deb
 94c12382f26554f7d0bbabdc285ef9d59750a8d0 8918 php5-pspell_5.4.4-14+deb7u7_amd64.deb
 6d48c26b45194284a277b998461dc5f0dd539fdd 5214 php5-recode_5.4.4-14+deb7u7_amd64.deb
 ba957e743ef6c2998e67d7b3d82f4714033bda8b 21820 php5-snmp_5.4.4-14+deb7u7_amd64.deb
 bc4f7f65d3913d6de4572bb00fdd323470ae8801 30352 php5-sqlite_5.4.4-14+deb7u7_amd64.deb
 90d3304b845d2008207d84086c46d55c058ad283 28456 php5-sybase_5.4.4-14+deb7u7_amd64.deb
 fc6244cd23ca9fcbec1ffeb06e1812dea951b426 19610 php5-tidy_5.4.4-14+deb7u7_amd64.deb
 8bd5ffd03cd69dcfa1fa12015f2870789f6aec61 36306 php5-xmlrpc_5.4.4-14+deb7u7_amd64.deb
 9192145a1d1278f12e73ef5eeaaa4444595d2684 15430 php5-xsl_5.4.4-14+deb7u7_amd64.deb
Checksums-Sha256: 
 a7dfa75913c9e9ec1bd3d4351f8f9f58372b5c23db7d4303b4875e490a4410b2 3774 php5_5.4.4-14+deb7u7.dsc
 266efe3362810b8d01cc7535e6cc2bc3907dc277c4af8824eb5990b168f55c26 224674 php5_5.4.4-14+deb7u7.diff.gz
 431cf54e891b5cc1fefc4aa08abfeef7c5277dd1959445e61ee3ed4ee3f01f49 1026 php5_5.4.4-14+deb7u7_all.deb
 9f54403a488bce95f0e41b6496c2f88f62b67f31ab99b1526847ee83bc348e9a 369272 php-pear_5.4.4-14+deb7u7_all.deb
 c7f4610ae9f48652ef450e1753e46021610a26bc4d84e2c28400ac48dcb7bc2a 588224 php5-common_5.4.4-14+deb7u7_amd64.deb
 a0731b0aa2b7732931d7c479e567ffdf2cf8a70a440ad0a209b76ca0c35f5a3b 2665644 libapache2-mod-php5_5.4.4-14+deb7u7_amd64.deb
 52bec75ebcd31bd137cdaaf8f705b17d25825ef8d2e8c183f4a41ea0dae516e2 2664020 libapache2-mod-php5filter_5.4.4-14+deb7u7_amd64.deb
 92543ccdb66bb240dcb7c6edf6b8d1f094ecda47035965ae774dcbdc25c39ff6 5100870 php5-cgi_5.4.4-14+deb7u7_amd64.deb
 c72e018bbd3baf04de6e7ef8f850cfc9a4c4a5b308da7fedf1f09b5547359271 2557440 php5-cli_5.4.4-14+deb7u7_amd64.deb
 8c791c0b417715e3b81eea73866f50bddcee65f49b8e01ebd3080cb7210a6603 2590524 php5-fpm_5.4.4-14+deb7u7_amd64.deb
 1ae86ad6e9b13aa2cf0c20878ef933634c25073cb52e51456284dd443c6db048 2662062 libphp5-embed_5.4.4-14+deb7u7_amd64.deb
 f5e9d7d575a94e24d08dad1c78b8d18c35eb648fa73f7a53b13d28f6b15cd00e 497438 php5-dev_5.4.4-14+deb7u7_amd64.deb
 87396d4e276dc3f7fd7934bf339c6ef14785e366d106e2532f5432ae18d99e28 15959722 php5-dbg_5.4.4-14+deb7u7_amd64.deb
 20d5fb56a5fdeda5c86f32833ce5b29b4d983742ee52e115ffc2348df1a9f648 29180 php5-curl_5.4.4-14+deb7u7_amd64.deb
 879ed3d02207f67ae846fc9dfb79d282ebd47bc86fbe5407e966f20e6b8b20b6 9946 php5-enchant_5.4.4-14+deb7u7_amd64.deb
 2d62819500676a910ca11f1aa27595b5210f36b7a49a6931bf88e07445ed407d 35720 php5-gd_5.4.4-14+deb7u7_amd64.deb
 cffeb5ef13c7953289c3a7dbee4dcd797ed68ea5557b4c80764ba06c4b5cff9f 17176 php5-gmp_5.4.4-14+deb7u7_amd64.deb
 5cad951dc61f8b032159724d2abc82c0533592cfdc279cd1c1c3798612a49bdb 35614 php5-imap_5.4.4-14+deb7u7_amd64.deb
 f9eda4004de4eee6b6b0637aac087e99e4f8140327de9f6dbc82a6f4300b9cf1 49612 php5-interbase_5.4.4-14+deb7u7_amd64.deb
 6616bb60365037165eb9c4b17a45dfcf47d25bd9e20842ae6ce4bce8a4ea5a03 71974 php5-intl_5.4.4-14+deb7u7_amd64.deb
 9cc2fbe8d7f23bf5dd83b1303b22900c290dd14f92c9f2f6e00d00905e30ac67 21774 php5-ldap_5.4.4-14+deb7u7_amd64.deb
 9cf8fd016a4f69443c3f45f7661067fc2d8b37ace351e4b4d9a60a9801af6b27 16096 php5-mcrypt_5.4.4-14+deb7u7_amd64.deb
 dd3425a26dc14911d1babc2fa49fc42540f5f9555ebeb18c3338cff37f976764 80866 php5-mysql_5.4.4-14+deb7u7_amd64.deb
 85dece646079668001a02713e91abb8e5783f9f982a2c229ec539961e579fc69 162732 php5-mysqlnd_5.4.4-14+deb7u7_amd64.deb
 2f45221c74b97479d7e735e5afca8166b6f496c28f8bd64e777047ead3407e7f 36416 php5-odbc_5.4.4-14+deb7u7_amd64.deb
 aba57579122f5e09c84df01f7a633e8334f441b7446a4ab2ebb75e14022d0773 61074 php5-pgsql_5.4.4-14+deb7u7_amd64.deb
 3362b94c57579119b3a2aea8d5df423e72cad489d1d1ca461ab8cd9d742be100 8918 php5-pspell_5.4.4-14+deb7u7_amd64.deb
 92a7cdbdf8fd6fd058c535072de43a1a37ae95ca78bc3fb825f75e0be0a5169a 5214 php5-recode_5.4.4-14+deb7u7_amd64.deb
 bebf10aa3c679e2b666beca06d76b283825e01dfb732fa19750e3db8c88276ee 21820 php5-snmp_5.4.4-14+deb7u7_amd64.deb
 b896960703fdd86effe6d1ea9c8f893b96d8d0144bc40f898b732be0825094a8 30352 php5-sqlite_5.4.4-14+deb7u7_amd64.deb
 0c3bc4b1fe3f6f33cd32f54e467c6d400c2424062b95656b39bd0dad97c09538 28456 php5-sybase_5.4.4-14+deb7u7_amd64.deb
 28e21aa5191fc3547b80d7c66d2e4e6c1b5ccf93bc554bac0883b081afb52e24 19610 php5-tidy_5.4.4-14+deb7u7_amd64.deb
 da60cefeb26d84cd5a089d567603d468b0454d4e4ba4c32ea586f9ddec71a36b 36306 php5-xmlrpc_5.4.4-14+deb7u7_amd64.deb
 3d0cd9124f0a7784d5d0989cf33131b73d0006bf336e282f5ea9bef90c95d9ad 15430 php5-xsl_5.4.4-14+deb7u7_amd64.deb
Files: 
 6bb319a9e0c78fd09df025b19e919704 3774 php optional php5_5.4.4-14+deb7u7.dsc
 a5448fd9b9142dfd132274dbddb08559 224674 php optional php5_5.4.4-14+deb7u7.diff.gz
 dbecdb6ad4a5fec5371fec22a55b6bcc 1026 php optional php5_5.4.4-14+deb7u7_all.deb
 431ce762368a7f3f80b55a3fd63dc0e5 369272 php optional php-pear_5.4.4-14+deb7u7_all.deb
 90a3b5aa93ca20c8bb6b10a013c3543e 588224 php optional php5-common_5.4.4-14+deb7u7_amd64.deb
 e4d39fc9d3dea4e30681a5b4ad3b5fb2 2665644 httpd optional libapache2-mod-php5_5.4.4-14+deb7u7_amd64.deb
 8762b560adb4643f78ef119914173a1a 2664020 httpd extra libapache2-mod-php5filter_5.4.4-14+deb7u7_amd64.deb
 5a31d15029c8ab82c35f029e08cdbecb 5100870 php optional php5-cgi_5.4.4-14+deb7u7_amd64.deb
 12dfecbdb8f369e5a4a5e9d3f1fbe6c2 2557440 php optional php5-cli_5.4.4-14+deb7u7_amd64.deb
 5364dc33928c74e1671e197ec5489e83 2590524 php optional php5-fpm_5.4.4-14+deb7u7_amd64.deb
 72de23f43a23a051ed5ab90b58252159 2662062 php optional libphp5-embed_5.4.4-14+deb7u7_amd64.deb
 8bbd0f91a963664e276ea01a204dc0a9 497438 php optional php5-dev_5.4.4-14+deb7u7_amd64.deb
 c50c99ae343779ed6c5fd85c38b5b3ab 15959722 debug extra php5-dbg_5.4.4-14+deb7u7_amd64.deb
 c88a37daa354eb53781cda83d2487cec 29180 php optional php5-curl_5.4.4-14+deb7u7_amd64.deb
 fbf88c769dcd85a376a9e361c7d235dc 9946 php optional php5-enchant_5.4.4-14+deb7u7_amd64.deb
 36462177a83483a15fe663f8275fbcc0 35720 php optional php5-gd_5.4.4-14+deb7u7_amd64.deb
 bc6aee606af394fde0352e6d59f8e2ea 17176 php optional php5-gmp_5.4.4-14+deb7u7_amd64.deb
 810d0a3a0faa01d7a994b35b203e9a07 35614 php optional php5-imap_5.4.4-14+deb7u7_amd64.deb
 77728d4cbccca6d9467b5eb79c6fd530 49612 php optional php5-interbase_5.4.4-14+deb7u7_amd64.deb
 7dab9e9e189f106352c31a9c49474881 71974 php optional php5-intl_5.4.4-14+deb7u7_amd64.deb
 e2cdab293fe921f38d01fcf9a29556d5 21774 php optional php5-ldap_5.4.4-14+deb7u7_amd64.deb
 0547f91fb82ead781e457fcfa78236d9 16096 php optional php5-mcrypt_5.4.4-14+deb7u7_amd64.deb
 cc1119a171ff912f941a7b0d24cc4f23 80866 php optional php5-mysql_5.4.4-14+deb7u7_amd64.deb
 44bcb46bee4189c0bc655481c5388174 162732 php extra php5-mysqlnd_5.4.4-14+deb7u7_amd64.deb
 b6a935f3bd2e91204fac0c80b7456f30 36416 php optional php5-odbc_5.4.4-14+deb7u7_amd64.deb
 c09de25160e50283978215df17a0e9a5 61074 php optional php5-pgsql_5.4.4-14+deb7u7_amd64.deb
 4592acf8d5fc245b6e67d64589e4638f 8918 php optional php5-pspell_5.4.4-14+deb7u7_amd64.deb
 acb2a611c1ae821772b26f4f3b9db891 5214 php optional php5-recode_5.4.4-14+deb7u7_amd64.deb
 3b4b2d1098fac93a6433bfe5e3887268 21820 php optional php5-snmp_5.4.4-14+deb7u7_amd64.deb
 be7dac2ad18d5c63f09d4b4331ed3500 30352 php optional php5-sqlite_5.4.4-14+deb7u7_amd64.deb
 5240b7b1793ea2b85861e5e8cc3b0c88 28456 php optional php5-sybase_5.4.4-14+deb7u7_amd64.deb
 b58a51560ec05ea81d216606f7e789af 19610 php optional php5-tidy_5.4.4-14+deb7u7_amd64.deb
 c2e46f8730c54d72bff03e50079aa405 36306 php optional php5-xmlrpc_5.4.4-14+deb7u7_amd64.deb
 318006868a749ce6105722e6daefd63b 15430 php optional php5-xsl_5.4.4-14+deb7u7_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlKpkXQACgkQ9OZqfMIN8nMqbgCgkPWbtQZJtF7DpCQz8kjD9BkR
Cz0An27zCfuxGluFb876xz5DEy6x7JGk
=OX+G
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 09 Feb 2014 07:35:49 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 13:32:34 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.