>> Debian Security Update Fixes PHP Denial of Service Vulnerability
Title : Debian Security Update Fixes PHP Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2005-0627 CVE ID : CVE-2005-0525 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-05-26
Technical Description
Debian has released a security patch to correct a vulnerability identified in PHP. This flaw is due to an input validation error in the "php_handle_iff()" and "php_handle_jpeg()" when processing specially crafted JPEG images, which may be exploited by attackers to cause a denial of service. For additional information, see : VUPEN/ADV-2005-0305
Debian GNU/Linux 3.0 (woody) - Upgrade to version 4.1.2-7.woody4
Debian GNU/Linux unstable (sid) - Upgrade to version 4.3.10-10
Debian GNU/Linux testing (sarge) - Upgrade to version 4.3.10-10 References