Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 144297 - dev-lang/php: 5.1.6 and 4.4.4 released
Summary: dev-lang/php: 5.1.6 and 4.4.4 released
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High minor
Assignee: PHP Bugs
URL: http://www.php.net/release_5_1_5.php
Whiteboard:
Keywords:
: 145208 (view as bug list)
Depends on:
Blocks:
 
Reported: 2006-08-18 03:48 UTC by Hanno Böck
Modified: 2006-08-29 13:01 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2006-08-18 03:48:11 UTC
From the release notes:

"This release provides the following security fixes: 
Added missing safe_mode/open_basedir checks inside the error_log(), file_exists(), imap_open() and imap_reopen() functions.
Fixed overflows inside str_repeat() and wordwrap() functions on 64bit systems.
Fixed possible open_basedir/safe_mode bypass in cURL extension and with realpath cache.
Fixed overflow in GD extension on invalid GIF images.
Fixed a buffer overflow inside sscanf() function.
Fixed an out of bounds read inside stripos() function.
Fixed memory_limit restriction on 64 bit system."
Comment 1 Sebastian Bergmann (RETIRED) gentoo-dev 2006-08-18 04:08:51 UTC
Although Luca can probably better comment on this, but we already have these security fixes in our PHP 4.4.3 and PHP 5.1.4 packages, respectively.
Comment 2 Luca Longinotti (RETIRED) gentoo-dev 2006-08-18 04:38:27 UTC
Yes all of those are already fixed in our 4.4.3-r1 and 5.1.4-r6 releases. Only little thing still open is the open_basedir/safe_mode bypass in imap_reopen(), the fix for that was added after we released our updated PHP packages, but we have the  fix for imap_open(). Since safe_mode/open_basedir stuff is not treated by security, de-CCing you guys. ;) 5.1.5 and 4.4.4 should be available in Portage between monday and wednesday, depends on when I have time. :) It's not particularly urgent, as there is no critical outstanding security stuff or bugs.
Best regards, CHTEKK.
Comment 3 Luca Longinotti (RETIRED) gentoo-dev 2006-08-18 04:39:45 UTC
Always miss those boxes...
Best regards, CHTEKK.
Comment 4 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-08-18 05:08:21 UTC
(In reply to comment #2)
> Yes all of those are already fixed in our 4.4.3-r1 and 5.1.4-r6 releases.

> Since safe_mode/open_basedir stuff is not
> treated by security, de-CCing you guys. ;) 

Perfect, thanks Luca.
Comment 5 Láďa Durchánek 2006-08-25 03:37:44 UTC
Don't hurry with 5.1.5, there is a 5.1.6 now :-)
Comment 6 Sebastian Bergmann (RETIRED) gentoo-dev 2006-08-25 04:03:14 UTC
Again: There is no hurry to add these new UPSTREAM versions to the tree as our current packages for both PHP 4 and PHP 5 already have all the security fixes backported, thanks to the effort of Luca.
Comment 7 Lars Strojny 2006-08-25 18:43:48 UTC
What is with the issue, the hardened Guys mentioned on http://www.hardened-php.net/hphp/zend_hash_del_key_or_index_vulnerability.html?
Comment 8 Luca Longinotti (RETIRED) gentoo-dev 2006-08-25 19:26:15 UTC
(In reply to comment #7)
> What is with the issue, the hardened Guys mentioned on
> http://www.hardened-php.net/hphp/zend_hash_del_key_or_index_vulnerability.html?

That was fixed upstream in 4.4.3 and 5.1.4, our stable packages thus reflect that and include the fix. Our 4.4.2 packages also had the fix for that bug since a long time now, as well as the previous 5.1.4 revisions (since 5.1.4 was released in May).
Best regards, CHTEKK.
Comment 9 Lars Strojny 2006-08-25 19:36:09 UTC
Ah, ok. Thanks for the information.
Comment 10 Conrad Kostecki gentoo-dev 2006-08-26 16:50:11 UTC
It would be nice to see PHP 5.1.6 in Portage ;)
Comment 11 Jakub Moc (RETIRED) gentoo-dev 2006-08-26 23:00:41 UTC
*** Bug 145208 has been marked as a duplicate of this bug. ***
Comment 12 Luca Longinotti (RETIRED) gentoo-dev 2006-08-29 13:01:49 UTC
PHP 4.4.4 and 5.1.6 with Hardened-PHP 0.4.14 are in the tree now, enjoy!
Best regards, CHTEKK.