|
HP-UX update for Apache with PHP
|
|
Secunia Advisory:
|
SA30040
|
|
|
Release Date:
|
2008-05-06
|
|
Last Update:
|
2008-05-20
|
|
Popularity:
|
4,864 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Security Bypass Privilege escalation DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | HP-UX 11.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2007-2872 CVE-2007-3378 CVE-2007-4783 CVE-2007-4840 CVE-2007-4887 CVE-2007-5898 CVE-2007-5899 CVE-2007-5900
|
|
Description: HP-UX has issued an update for Apache with PHP. This fixes some vulnerabilities, which can be exploited by malicious users and malicious people to bypass certain security restrictions, gain escalated privileges, or cause a DoS (Denial of Service).
For more information:
SA25456
SA26642
The vulnerabilities affect HP-UX B.11.11, B.11.23, B.11.31 running Apache v2.18 with PHP v5.2.4 or earlier.
Solution: Apply updates.
HP-UX B.11.11:
hpuxwsAPACHE.PHP
hpuxwsAPACHE.PHP2
Install revision B.2.0.59.04.01 or subsequent and restart Apache
ftp://srt80056:srt80056@hprc.external.hp.com
HP-UX B.11.23:
hpuxwsAPCH32.PHP
hpuxwsAPCH32.PHP2
hpuxwsAPACHE.PHP
hpuxwsAPACHE.PHP2
Install revision B.2.0.59.04.01 or subsequent and restart Apache
ftp://srt80056:srt80056@hprc.external.hp.com
HP-UX B.11.31:
hpuxwsAPCH32.PHP
hpuxwsAPCH32.PHP2
hpuxwsAPACHE.PHP
hpuxwsAPACHE.PHP2
Install revision B.2.0.59.04.01 or subsequent and restart Apache
ftp://srt80056:srt80056@hprc.external.hp.com
Changelog: 2008-05-20: Updated "Solution" and "Description" sections.
Original Advisory: HPSBUX02332 SSRT080056:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438646
Other References: SA25456:
http://secunia.com/advisories/25456/
SA26642:
http://secunia.com/advisories/26642/
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|