Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:  Thu, 15 Oct 2009 18:47:15 -0500
From:  Raphael Geissert <geissert@...ian.org>
To: oss-security@...ts.openwall.com
Subject:  Re: CVE Request -- PHP 5 - 5.2.11

Steven M. Christey wrote:

> 
> ======================================================
> Name: CVE-2009-3291
> 
> The php_openssl_apply_verification_policy function in PHP before
> 5.2.11 does not properly perform certificate validation, which has
> unknown impact and attack vectors, probably related to an ability to
> spoof certificates.
> 

Yes, seems to be related to an improper handling of \0 in the CN field.

> 
> ======================================================
> Name: CVE-2009-3292
>
> Unspecified vulnerability in PHP before 5.2.11 has unknown impact and
> attack vectors related to "missing sanity checks around exif
> processing."
>

It is related to missing sanity checks when determining the length of
sections of jpg headers and a missing limit on the nesting level of TIFF
files.

Regards,
-- 
Raphael Geissert - Debian Developer
www.debian.org - get.debian.net


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ