First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 39952
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Carsten Lohrke <carlo@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 39952 depends on: Show dependency tree
Bug 39952 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-01-31 03:14 0000
http://bugs.php.net/bug.php?id=25753
http://chora.php.net/cvs.php/php-src/sapi/apache2handler/sapi_apache2.c?login=2&onb=1.1.2

------- Comment #1 From Tim Yamin (RETIRED) 2004-01-31 07:05:27 0000 -------
Patch from CVS:
http://chora.php.net/diff.php/php-src/sapi/apache2handler/sapi_apache2.c?login=2&r1=1.1.2.25&r2=1.1.2.26&ty=u

------- Comment #2 From Tim Yamin (RETIRED) 2004-01-31 07:24:19 0000 -------
I forgot to add that we also have
http://chora.php.net/diff.php/php-src/sapi/apache/mod_php5.c?login=2&r1=1.7&r2=1.8&ty=u
for Apache 1.x.

------- Comment #3 From Stuart Herbert (RETIRED) 2004-01-31 13:36:54 0000 -------
Yuk.  Working on new ebuilds now.

Stu

------- Comment #4 From Tim Yamin (RETIRED) 2004-01-31 13:54:05 0000 -------
GLSA:
http://dev.gentoo.org/~plasmaroo/glsa-test/frame-view.php?id=f965592d37edc1c43fa7152d3ed60d87

------- Comment #5 From Stuart Herbert (RETIRED) 2004-01-31 14:41:56 0000 -------
Okay, a patch for apache1 and apache2 has been committed.  mod_php-4.3.4-r3 has
been marked as ~arch until robbat2 has had a chance to look at it.

I'm happy with this on apache2.  Someone needs to test this on apache1.  I
don't have a machine I can downgrade to apache1 for testing this.

Stu

------- Comment #6 From Stuart Herbert (RETIRED) 2004-01-31 15:02:08 0000 -------
Of course, it helps if I patch *all* the occurances of this problem that
plasmaroo found ... ;-)

New patch committed to CVS.

------- Comment #7 From solar 2004-01-31 15:05:20 0000 -------
Do we set register globals on or off by default?

------- Comment #8 From Tim Yamin (RETIRED) 2004-01-31 15:08:17 0000 -------
Thanks Stuart - now over to the
Ned-or-Rajiv-or-Somebody-please-approve-this-GLSA department.

------- Comment #9 From Tim Yamin (RETIRED) 2004-01-31 15:09:57 0000 -------
23:09 <@Stuart> plasmaroo: it should ship with 'register globals' set to off

------- Comment #10 From solar 2004-01-31 18:29:57 0000 -------
plasmaroo,
Can you please note in the Impact of the GLSA that Gentoo ships/builds php with register globals off.

------- Comment #11 From Robin Johnson 2004-01-31 23:55:13 0000 -------
stuart: all looks ok, go ahead and move it to x86.

------- Comment #12 From Tim Yamin (RETIRED) 2004-02-08 03:03:05 0000 -------
GLSA 200402-01 was sent out, so this can be closed.

First Last Prev Next    No search results available      Search page      Enter new bug