Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 277293 - <=dev-php5/eaccelerator-0.9.5.3 encoder.php remote code execution (CVE-2009-2353)
Summary: <=dev-php5/eaccelerator-0.9.5.3 encoder.php remote code execution (CVE-2009-2...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~1 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-07-10 08:51 UTC by Alex Legler (RETIRED)
Modified: 2009-08-14 11:00 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2009-07-10 08:51:12 UTC
CVE-2009-2353 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2353):
  encoder.php in eAccelerator allows remote attackers to execute
  arbitrary code by copying a local executable file to a location under
  the web root via the -o option, and then making a direct request to
  this file, related to upload of image files.
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-14 11:00:56 UTC
+*eaccelerator-0.9.5.3-r1 (14 Aug 2009)
+
+  14 Aug 2009; Alex Legler <a3li@gentoo.org> -eaccelerator-0.9.5.1.ebuild,
+  -files/eaccelerator-0.9.5.1-optimize-catch-exceptions.patch,
+  -eaccelerator-0.9.5.3.ebuild, +eaccelerator-0.9.5.3-r1.ebuild,
+  +files/eaccelerator-remove-encoder.patch:
+  Non-mainatiner commit: Removing encoder because it a) contains a
+  vulnerabilitiy and b) is already deprecated by upstream and will be gone
+  anyway in the next upstream release. Security bug 277293. Removing
+  vulnerable versions.

Closing.