php5 5.0.5-2ubuntu1.2 source package in Ubuntu

Changelog

php5 (5.0.5-2ubuntu1.2) breezy-security; urgency=low

  * SECURITY UPDATE: multiple fixes backported from 5.1.2 and CVS:
    - Fix multiple HTTP response splitting vulnerabilities in sessions and
      the header() function, due to lack of input validation; CVE-2006-0207
      + Add safety checks in the header() function to make sure that we
        don't get newlines injected by (mis)use of user input in headers.
      + Add a check for invalid characters in session names, so that we
        aren't subject to HTTP response splitting vulnerabilities in
        the Set-Cookie header we send back out as a result of user input.
      + Bring in a patch that got lost between php4 and php5, preventing
        us from sending session cookies when we were just handed one,
        unless the session ID has changed, eliminating another vector.
    - Filter HTML error reporting, preventing cross-site scripting attacks
      when both display_errors and html_errors are enabled; CVE-2006-0208

 -- Adam Conrad <email address hidden>   Wed,  8 Mar 2006 17:10:37 +1100

Upload details

Uploaded by:
Adam Conrad
Uploaded to:
Breezy
Original maintainer:
Debian PHP Maintainers
Architectures:
any
Section:
web
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
php5_5.0.5.orig.tar.gz 5.8 MiB 9352f178a3ad5cf85820ee9b6e74de96b997ef55958c5f0315b6e8eb1369d552
php5_5.0.5-2ubuntu1.2.diff.gz 100.4 KiB 30e9f1a60fe7cc28eb532da85b2966f3030c63a94eff7bd7a419502c2a869a86
php5_5.0.5-2ubuntu1.2.dsc 1.7 KiB 11799d9959e31fd68a1702a678aa1ac3f38f07258ae3a92a0fc645fbb2dde63e

View changes file

Binary packages built by this source

libapache2-mod-php5: No summary available for libapache2-mod-php5 in ubuntu breezy.

No description available for libapache2-mod-php5 in ubuntu breezy.

php-pear: No summary available for php-pear in ubuntu breezy.

No description available for php-pear in ubuntu breezy.

php5: No summary available for php5 in ubuntu breezy.

No description available for php5 in ubuntu breezy.

php5-cgi: No summary available for php5-cgi in ubuntu breezy.

No description available for php5-cgi in ubuntu breezy.

php5-cli: No summary available for php5-cli in ubuntu breezy.

No description available for php5-cli in ubuntu breezy.

php5-common: No summary available for php5-common in ubuntu breezy.

No description available for php5-common in ubuntu breezy.

php5-curl: No summary available for php5-curl in ubuntu breezy.

No description available for php5-curl in ubuntu breezy.

php5-dev: No summary available for php5-dev in ubuntu breezy.

No description available for php5-dev in ubuntu breezy.

php5-gd: No summary available for php5-gd in ubuntu breezy.

No description available for php5-gd in ubuntu breezy.

php5-ldap: No summary available for php5-ldap in ubuntu breezy.

No description available for php5-ldap in ubuntu breezy.

php5-mhash: No summary available for php5-mhash in ubuntu breezy.

No description available for php5-mhash in ubuntu breezy.

php5-mysql: No summary available for php5-mysql in ubuntu breezy.

No description available for php5-mysql in ubuntu breezy.

php5-odbc: No summary available for php5-odbc in ubuntu breezy.

No description available for php5-odbc in ubuntu breezy.

php5-pgsql: No summary available for php5-pgsql in ubuntu breezy.

No description available for php5-pgsql in ubuntu breezy.

php5-recode: No summary available for php5-recode in ubuntu breezy.

No description available for php5-recode in ubuntu breezy.

php5-snmp: No summary available for php5-snmp in ubuntu breezy.

No description available for php5-snmp in ubuntu breezy.

php5-sqlite: No summary available for php5-sqlite in ubuntu breezy.

No description available for php5-sqlite in ubuntu breezy.

php5-sybase: No summary available for php5-sybase in ubuntu breezy.

No description available for php5-sybase in ubuntu breezy.

php5-xmlrpc: No summary available for php5-xmlrpc in ubuntu breezy.

No description available for php5-xmlrpc in ubuntu breezy.

php5-xsl: No summary available for php5-xsl in ubuntu breezy.

No description available for php5-xsl in ubuntu breezy.