It was possible to conduct an XSS attack via the HTTP_HOST variable; also, some scripts in the libraries directory that handle header generation were vulnerable to XSS.
web-apps please bump.
2.7.0 is already in the tree
Thx Renat. Arches please test and mark stable.
stable on x86
Stable on ppc and hppa.
http://www.hardened-php.net/advisory_252005.110.html They also list local and remote file inclusion
*** Bug 114728 has been marked as a duplicate of this bug. ***
2.7.0-pl1 is released with another security fix. web-apps please bump.
In CVS.
arches, your good old friend phpmyadmin again - pls test and mark stable, thx a lot
Stable on amd64.
Stable on alpha. gustavoz (or sparc family) your turn ;)
sparc stable.
Ready for GLSA
GLSA 200512-03