|
|
>> Mandriva Security Update Fixes PEAR XML-RPC Vulnerability
|
Title : Mandriva Security Update Fixes PEAR XML-RPC Vulnerability VUPEN ID : VUPEN/ADV-2005-1502 CVE ID : CVE-2005-2498 CWE ID : CWE-
Rated as : High Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-08-23
|
Mandriva has released updated packages to correct a vulnerability identified in Pear XML-RPC. This flaw is due to an input validation error when processing, via the "eval()" call, certain XML tags nested in parsed documents, which could be exploited by remote attackers to execute arbitrary PHP commands. For additional information, see : VUPEN/ADV-2005-1412
Affected Products
Mandrakelinux 10.0
Mandrakelinux 10.1
Corporate Server 3.0
Mandrivalinux LE2005
Solution
Use MandrakeUpdate to apply patches :
Mandrakelinux 10.0
ad5790382b19a06f31d341d7eba05fb6 10.0/RPMS/php-pear-4.3.4-3.2.100mdk.noarch.rpm
7d41047a2fb997725773ae9dccd76ff9 10.0/SRPMS/php-pear-4.3.4-3.2.100mdk.src.rpm
Mandrakelinux 10.0/AMD64
ad5790382b19a06f31d341d7eba05fb6 amd64/10.0/RPMS/php-pear-4.3.4-3.2.100mdk.noarch.rpm
7d41047a2fb997725773ae9dccd76ff9 amd64/10.0/SRPMS/php-pear-4.3.4-3.2.100mdk.src.rpm
Mandrakelinux 10.1
3c0b4ed15139d42df9be6ed177a571d6 10.1/RPMS/php-pear-4.3.8-1.2.101mdk.noarch.rpm
ffd4b96fe8e05b7246eccd881563229d 10.1/SRPMS/php-pear-4.3.8-1.2.101mdk.src.rpm
Mandrakelinux 10.1/X86_64
3c0b4ed15139d42df9be6ed177a571d6 x86_64/10.1/RPMS/php-pear-4.3.8-1.2.101mdk.noarch.rpm
ffd4b96fe8e05b7246eccd881563229d x86_64/10.1/SRPMS/php-pear-4.3.8-1.2.101mdk.src.rpm
Corporate Server 3.0
4f1eede09f0e47209b13e7c8168bcb79 corporate/3.0/RPMS/php-pear-4.3.4-3.2.C30mdk.noarch.rpm
e5e1fa37415a8761c2b25799ef8fffb5 corporate/3.0/SRPMS/php-pear-4.3.4-3.2.C30mdk.src.rpm
Corporate Server 3.0/X86_64
4f1eede09f0e47209b13e7c8168bcb79 x86_64/corporate/3.0/RPMS/php-pear-4.3.4-3.2.C30mdk.noarch.rpm
e5e1fa37415a8761c2b25799ef8fffb5 x86_64/corporate/3.0/SRPMS/php-pear-4.3.4-3.2.C30mdk.src.rpm
Mandrivalinux LE2005
484af9862c08f5fdec98007d74fdcf8c 10.2/RPMS/php-pear-4.3.10-3.2.102mdk.noarch.rpm
28e358ce40a0561251ba34d909a7c617 10.2/SRPMS/php-pear-4.3.10-3.2.102mdk.src.rpm
Mandrivalinux LE2005/X86_64
484af9862c08f5fdec98007d74fdcf8c x86_64/10.2/RPMS/php-pear-4.3.10-3.2.102mdk.noarch.rpm
28e358ce40a0561251ba34d909a7c617 x86_64/10.2/SRPMS/php-pear-4.3.10-3.2.102mdk.src.rpm
References
http://www.vupen.com/english/advisories/2005/1502 http://www.mandriva.com/security/advisories?name=MDKSA-2005:146
ChangeLog
2005-08-23 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|