| 
 | 
 
Debian最新安全更新 php5 代码注入 
 
配置变量有缺陷 允许远程攻击者可以崩溃PHP或潜在的执行代码. 
建议更新 
Package        : php5 
Vulnerability  : code injection 
Problem type   : remote 
Debian-specific: no 
CVE ID         : CVE-2012-0830 
 
Stefan Esser discovered that the implementation of the max_input_vars 
configuration variable in a recent PHP security update was flawed such 
that it allows remote attackers to crash PHP or potentially execute 
code. 
 
This update adds packages for the oldstable distribution, which were 
missing from the original advisory. The problem has been fixed in 
version 5.2.6.dfsg.1-1+lenny16, installed into the security archive 
on 3 Feb 2012. 
 
For the stable distribution (squeeze), this problem has been fixed in 
version 5.3.3-7+squeeze7. 
 
For the unstable distribution (sid), this problem has been fixed in 
version 5.3.10-1. 
 
We recommend that you upgrade your php5 packages. |   
 
 
 
 |