Family: Slackware Local Security Checks --> Category: infos
SSA-2005-242-02 PHP Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
New PHP packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1,
and -current to fix security issues. PHP has been relinked with the
shared PCRE library to fix an overflow issue with PHP's builtin PRCE
code, and PEAR::XMLRPC has been upgraded to version 1.4.0 which
eliminates the eval() function. The eval() function is believed to be
insecure as implemented, and would be difficult to secure.
Note that these new packages now require that the PCRE package be
installed, so be sure to get the new package from the patches/packages/
directory if you don't already have it. A new version of this (6.3)
was also issued today, so be sure that is the one you install.
More details about these issues may be found in the Common
Vulnerabilities and Exposures (CVE) database:
Click HERE for more information and discussions on this network vulnerability scan.