Mandriva: Updated php-apc packages fix vulnerability


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) Mandriva: Updated php-apc packages fix vulnerability
# 1  
Old 04-14-2008
Mandriva: Updated php-apc packages fix vulnerability

LinuxSecurity.com: Daniel Papasian discovered a stack-based buffer overflow in the apc_search_paths() function in APC that can be triggered when processing long filenames. A remote attacker could exploit this vulnerability to execute arbitrarty code in PHP applications that pass user-controlled input to the include() function. The updated packages have been patched to correct these issues.

More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question
whohas(1)																 whohas(1)

NAME
whohas - find packages in various distributions' repositories SYNTAX
whohas [--no-threads] [--shallow] [--strict] [-d Dist1[,Dist2[,Dist3 etc.]]] pkgname DESCRIPTION
whohas is a command line tool to query package lists from the Arch, Debian, Fedora, Gentoo, Mandriva, openSUSE, Slackware (and linuxpack- ages.net), Source Mage, Ubuntu, FreeBSD, NetBSD, OpenBSD, Fink, MacPorts and Cygwin distributions. OPTIONS
--no-threads Don't use multiple threads to query package lists (will be much slower) --shallow Limit to one call per server. Faster, but loses some information, typically package size and release date. --strict List only those packages that have exactly pkgname as their name. -d Dist1[,Dist2[,Dist3 etc.]] Queries only for packages for the listed distributions. Recognised values for Dist1, Dist2, etc. are "archlinux", "cygwin", "debian", "fedora", "fink", "freebsd", "gentoo", "mandriva", "macports", "netbsd", "openbsd", "opensuse", "slackware", "sourcemage", and "ubuntu". pkgname Package name to query for FILES
whohas uses various files in ~/.whohas to cache package lists for some distributions. SEE ALSO
See intro.txt or intro.html notes on using whohas. AUTHORS
whohas is written and maintained by Philipp Wesche <phi1ipp@yahoo.com> This man page was written by Jonathan Wiltshire <debian@jwiltshire.org.uk> for the Debian project and adapted for a new version by Philipp Wesche <phi1ipp@yahoo.com> Jonathan Wiltshire 0.29 whohas(1)