"The PHP development team would like to announce the immediate
availability of PHP 5.2.3. This release continues to improve the
security and the stability of the 5.X branch as well as addressing
two regressions introduced by the previous 5.2 releases. These
regressions relate to the timeout handling over non-blocking SSL
connections and the lack of HTTP_RAW_POST_DATA in certain conditions.
All users are encouraged to upgrade to this release."
php please advise and patch as necessary.
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 184.108.40.206, when Internet Explorer 6 is used, allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2855.
This is probably unrelated, isn't it? You probably meant CVE-2007-2756.
Thx Lubomir, it was a typo.
There is a fix¹ for the broken fix for the chunk_split() issue. Guess our poor php souls know already. One can only shake his head...
php please advise.
Created attachment 121589 [details, diff]
Updated ebuild for php-5.2.3
I attached an ebuild for php-5.2.3. While the change to the ebuild was pretty easy (sapi/cgi/php is now called sapi/cgi/php-cgi) the patchset needed some bigger changes.
These were the changes as far as I can remember (in comparison to 5.2.2 patchset):
* manually reapplied php5-make_test.patch and regenerated patch
* copied all other patches from there, they still apply cleanly
* had to reapply and manually fix some hunks for php5.2.3-fastbuild.patch -- it now applies cleanly again and build works; didn't do any extensive tests though
* copied all other patches from there
* (ex 5.2.2/; now:) 5.2.3/
* copied php5.2.2-dba_config.patch, php5.2.2-mysql-charsetphpini.patch, php5.2.2-mysqli-charsetphpini.patch, php5.2.2-pdo_mysql-charsetphpini.patch
* dropped all other patches
* added a lot of fixes from php-cvs which i considered worth adding:
* php5.2.3-chunk_split-fix2.patch (this is the one mentioned in comment 4)
* php5.2.3-fix-simplexml-segfault-41582.patch: see http://bugs.php.net/bug.php?id=41582
* php5.2.3-gd-better-image-dimension-checks.patch: http://cvs.php.net/viewvc.cgi/php-src/ext/gd/gd.c?r1=1.3220.127.116.11.26&r2=1.318.104.22.168.27&pathrev=PHP_5_2
* php5.2.3-gd-fix-integer-overflows.patch: http://cvs.php.net/viewvc.cgi/php-src/ext/gd/gd.c?r1=1.322.214.171.124.28&r2=1.3126.96.36.199.29&pathrev=PHP_5_2 http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/gd.c?r1=188.8.131.52.2.11&r2=184.108.40.206.2.12&pathrev=PHP_5_2
* php5.2.3-gd-gif-invalid-color-index-segfault.patch: http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/gd_gif_in.c?r1=220.127.116.11.2.11&r2=18.104.22.168.2.12&pathrev=PHP_5_2 http://bugs.php.net/bug.php?id=41630
* php5.2.3-mopb-02-2007-improvement.patch: http://cvs.php.net/viewvc.cgi/php-src/main/php_variables.c?r1=22.214.171.124.2.8&r2=126.96.36.199.2.9&pathrev=PHP_5_2
* php5.2.3-php_admin-vs-ini_set.patch: http://cvs.php.net/viewvc.cgi/ZendEngine2/zend_ini.c?r1=188.8.131.52.2.8&r2=184.108.40.206.2.9&pathrev=PHP_5_2 http://bugs.php.net/bug.php?id=41561 (circumvention of ini settings set bei php_admin_* apache config flags)
* php5.2.3-strripos-fix-segfault.patch: http://cvs.php.net/viewvc.cgi/php-src/ext/standard/string.c?r1=1.4220.127.116.11.62&r2=1.418.104.22.168.63&pathrev=PHP_5_2
* php5.2.3-ze2-segfault-object+switch.patch: http://cvs.php.net/viewvc.cgi/ZendEngine2/zend_execute.c?r1=1.722.214.171.124.19&r2=1.7126.96.36.199.20&pathrev=PHP_5_2 http://bugs.php.net/bug.php?id=41608
* php5.2.3-zip-addEmptyDir-fix-crash.patch: http://cvs.php.net/viewvc.cgi/php-src/ext/zip/php_zip.c?r1=188.8.131.52&r2=184.108.40.206&pathrev=PHP_5_2
So most of these patches fix segfaults or some kind of overflows. I hardly have any C knowledge and as such I cannot judge if those overflows could be exploited in any way, but I thought it's always better to fix them even if there is no security problem as they are at least annoying.
All those patches belong to a patchset tar ball which can be found here: http://home.hoffie.info/php-patchset-5.2.3-r1.tar.bz2 
The attached ebuild will not work unless CHTEKK uploads the proper patchset tarball to his server.
Meanwhile, I have modified the ebuild to instead download that patchset from above url; the modified ebuild is located here: http://home.hoffie.info/php-5.2.3.ebuild 
I'm going to attach the output of svn diff for the php overlay as well.
I hope this contribution helps a bit.
 I know that one is not supposed to reference externally hosted data if possible, but the patchset tarball and the modified ebuild are just there for convenience, all important data (for developers) is attached to this bug. Also, I didn't want to pollute this bug with redundant attachments.
Created attachment 121591 [details, diff]
svn diff (overlays.g.o/proj/php) to get all necessary changes (updated patches)
Created attachment 121740 [details, diff]
updated svn diff, including the exif patch
"Fixed memory corruption when reading exif data of a non-file" doesn't sound like it should remain unpatched either, so I suggest additionally adding http://cvs.php.net/viewvc.cgi/php-src/ext/exif/exif.c?r1=220.127.116.11.2.19&r2=18.104.22.168.2.20&pathrev=PHP_5_2
I updated the svn diff attachment and the php-patchset tarball on my server.
*** Bug 182801 has been marked as a duplicate of this bug. ***
Created attachment 122723 [details, diff]
php-overlay: svn diff (including important patches from php-cvs up to June 21th)
And yet another bunch of new patches:
References included in file PATCHES.
Tarball on my server updated, updated svn diff attached.
Please tell me if posting the updated patchsets creates to much noise... I'm just trying to make pushing the update as easy as possible for CHTEKK, who seems to be busy with exams.
Don't know if this is worth opening another bug:
This flood of php-vulnerabilities is scary...
*** Bug 184324 has been marked as a duplicate of this bug. ***
Any news on this?
IIRC CHTEKK is busy with some exams, so is anybody else going to take care
of this not so unimportant update?
(In reply to comment #13)
> Any news on this?
> IIRC CHTEKK is busy with some exams, so is anybody else going to take care
> of this not so unimportant update?
Approx. two weeks ago, CHTEKK gave me access to the php-experimental overlay, and as such my work regarding php-5.2.3 is currently done there. That's why I didn't post any updates in this bug.
AFAIK CHTEKK won't have much time in the future either as he is currently doing his military service. He said that he will be at home at the weekends, but I don't know if this still applies and whether he will have time for PHP then.
(In reply to comment #11)
> Don't know if this is worth opening another bug:
I have still not found a patch to fix this issue, but I just committed a patch to the php overlay (not part of any patchset yet) which at least fixes the mail.force_extra_parameters shell command injection problem, so it basically makes the exploit useless. However, it still doesn't fix the initial problem.
Are you going to push PHP 5.2.3 into Portage?
I can't since I'm no Gentoo Developer. And proxy-maintaing something big like this.. I don't know whether this would be a good idea.
Anyway, I plan to continue working in php-experimental and if any dev feels like merging the work from there to the tree I certainly don't have any objections (as long as CHTEKK agrees ;)).
Christian please post here when you have an updated ebuild in the overlay.
(In reply to comment #14)
> (In reply to comment #11)
> > Don't know if this is worth opening another bug:
> > http://securityreason.com/achievement_securityalert/45
> I have still not found a patch to fix this issue, but I just committed a patch
> to the php overlay (not part of any patchset yet) which at least fixes the
> mail.force_extra_parameters shell command injection problem, so it basically
> makes the exploit useless. However, it still doesn't fix the initial problem.
It was me being a bit blind while watching cvs commits. Both a fix for error_log and session.save_path have been in CVS for 4 days. They are included in our latest patchset now.
(In reply to comment #17)
> Christian please post here when you have an updated ebuild in the overlay.
dev-lang/php-5.2.3-r2 is in the overlay now. It includes the fix(es) for CVE-2007-3378 (this is the same as above mentioned securityreason URL) and for yet another crash bug (http://bugs.php.net/bug.php?id=41919).
Thx Christian. Now we just need someone to check and commit before calling arches...
(In reply to comment #19)
> Thx Christian. Now we just need someone to check and commit before calling
As I was running 5.2.3-r2 from the overlay on a couple of boxes with no problems so far I wouldn't mind comitting -r3 - if someone from the php allows me to do so (or is the complete php herd somewhat away?)
(In reply to comment #20)
> As I was running 5.2.3-r2 from the overlay on a couple of boxes with no
> problems so far I wouldn't mind comitting -r3 - if someone from the php allows
> me to do so (or is the complete php herd somewhat away?)
read: was running -r1, wouldn't mind committing -r2 *sigh*
*** Bug 185586 has been marked as a duplicate of this bug. ***
I give my approval to commit the latest PHP 5.2.3 from the PHP Overlay, follow hoffie's judgement on this, as I trust him and he's atm much more on top of PHP things than I am... Sorry for the long delays.
Best regards, CHTEKK.
php-5.2.3-r3 is in the overlay now, it includes the fix for our bug 185586 and an additional crash fix for some SPL/ArrayObject stuff.
dertobi123 is going to commit this soon.
The following tests are known to fail:
double to string conversion tests [Zend/tests/double_to_string.phpt]
Bug #16069 (ICONV transliteration failure) [ext/iconv/tests/bug16069.phpt]
iconv stream filter [ext/iconv/tests/iconv_stream_filter.phpt]
touch() tests [ext/standard/tests/file/touch.phpt]
phpinfo() CGI [ext/standard/tests/general_functions/phpinfo2.phpt]
CLI long options [sapi/cli/tests/015.phpt]
There are probably more test failures (with some extensions).
I just committed 5.2.3-r3. Please note the changed behaviour wrt open_basedir and session.save_path, you might want to add a note about this to the GLSA (if there's one).
Arches please test and mark stable. Target keywords are:
"alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86 ~x86-fbsd"
Stable for HPPA.
This one is ready for GLSA vote. Note that we should probably wait for bug #187120.
I vote yes pending bug #187120, which'll probably bump us up another rev at least.
OK, arches please test and stabilize php-5.2.4_pre200708051230-r2. Most importantly, it fixes the apache segfaults in Bug 187120 (the session behaviour change regarding open_basedir/safe_mode was reverted upstream by the new patch). Other fixes include:
- floating point exception inside wordwrap()
- ArrayObject::exchangeArray hangs Apache (PHP bug #41691).
plus a bunch of others, unrelated to security.
Back to stable to get the regression fixed. Arches please test and mark stable.
PHP 5.2.4 RC1 Released
(In reply to comment #43)
> PHP 5.2.4 RC1 Released
Thanks, but this snapshot is *newer* than RC1.
Created attachment 131973 [details]
Comprehensive list of security issues fixed here.
GLSA 200710-02, sorry for the delay.