Back to php5 PTS page

Accepted php5 5.4.44-0+deb7u1 (source all amd64) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 16 Aug 2015 11:44:10 +0200
Source: php5
Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm libphp5-embed php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-imap php5-interbase php5-intl php5-ldap php5-mcrypt php5-mysql php5-mysqlnd php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl
Architecture: source all amd64
Version: 5.4.44-0+deb7u1
Distribution: wheezy-security
Urgency: medium
Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>
Changed-By: Ondřej Surý <ondrej@debian.org>
Description: 
 libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module)
 libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo
 libphp5-embed - HTML-embedded scripting language (Embedded SAPI library)
 php-pear   - PEAR - PHP Extension and Application Repository
 php5       - server-side, HTML-embedded scripting language (metapackage)
 php5-cgi   - server-side, HTML-embedded scripting language (CGI binary)
 php5-cli   - command-line interpreter for the php5 scripting language
 php5-common - Common files for packages built from the php5 source
 php5-curl  - CURL module for php5
 php5-dbg   - Debug symbols for PHP5
 php5-dev   - Files for PHP5 module development
 php5-enchant - Enchant module for php5
 php5-fpm   - server-side, HTML-embedded scripting language (FPM-CGI binary)
 php5-gd    - GD module for php5
 php5-gmp   - GMP module for php5
 php5-imap  - IMAP module for php5
 php5-interbase - interbase/firebird module for php5
 php5-intl  - internationalisation module for php5
 php5-ldap  - LDAP module for php5
 php5-mcrypt - MCrypt module for php5
 php5-mysql - MySQL module for php5
 php5-mysqlnd - MySQL module for php5 (Native Driver)
 php5-odbc  - ODBC module for php5
 php5-pgsql - PostgreSQL module for php5
 php5-pspell - pspell module for php5
 php5-recode - recode module for php5
 php5-snmp  - SNMP module for php5
 php5-sqlite - SQLite module for php5
 php5-sybase - Sybase / MS SQL Server module for php5
 php5-tidy  - tidy module for php5
 php5-xmlrpc - XML-RPC module for php5
 php5-xsl   - XSL module for php5
Changes: 
 php5 (5.4.44-0+deb7u1) wheezy-security; urgency=medium
 .
   * New upstream version 5.4.44
    - Core:
     . Fixed bug #69793 (Remotely triggerable stack exhaustion via recursive
       method calls).
     . Fixed bug #69892 (Different arrays compare indentical due to integer key
       truncation).
     . Fixed bug #70121 (unserialize() could lead to unexpected methods execution
       / NULL pointer deref).
    - OpenSSL:
     . Fixed bug #70014 (openssl_random_pseudo_bytes() is not cryptographically
       secure).
    - Phar:
     . Improved fix for bug #69441.
     . Fixed bug #70019 (Files extracted from archive may be placed outside of
       destination directory).
    - SOAP:
     . Fixed bug #70081 (SoapClient info leak / null pointer dereference via
        multiple type confusions).
    - SPL:
     . Fixed bug #70068 (Dangling pointer in the unserialization of ArrayObject
       items).
     . Fixed bug #70166 (Use After Free Vulnerability in unserialize() with
       SPLArrayObject).
     . Fixed bug #70168 (Use After Free Vulnerability in unserialize() with
       SplObjectStorage).
     . Fixed bug #70169 (Use After Free Vulnerability in unserialize() with
       SplDoublyLinkedList).
   * New upstream version 5.4.43
    - Core:
     . Fixed bug #69768 (escapeshell*() doesn't cater to !).
     . Fixed bug #69874 (Can't set empty additional_headers for mail()), regression
       from fix to bug #68776.
 .
    - Mysqlnd:
     . Fixed bug #69669 (mysqlnd is vulnerable to BACKRONYM) (CVE-2015-3152).
    - Phar:
     . Fixed bug #69958 (Segfault in Phar::convertToData on invalid file).
     . Fixed bug #69923 (Buffer overflow and stack smashing error in
       phar_fix_filepath).
   * Rebase patches on top of 5.4.44 release
 .
 php5 (5.4.42-0+deb7u1) wheezy-security; urgency=medium
 .
   * New upstream version 5.4.42
     (CVE-2015-4643, CVE-2015-4644, CVE-2015-4598)
    - Core:
     . Improved fix for bug #69545 (Integer overflow in ftp_genlist() resulting in
       heap overflow).
     . Fixed bug #69646 (OS command injection vulnerability in escapeshellarg).
     . Fixed bug #69719 (Incorrect handling of paths with NULs).
    - Litespeed SAPI:
     . Fixed bug #68812 (Unchecked return value).
    - Mail:
     . Fixed bug #68776 (mail() does not have mail header injection prevention for
       additional headers).
    - Postgres:
     . Fixed bug #69667 (segfault in php_pgsql_meta_data).
    - Sqlite3:
     . Upgrade bundled sqlite to 3.8.10.2.
   * Refresh patches using gbp pq (rebase)
Checksums-Sha1: 
 a1a563a82285498fb62c0680788aeae0c53373fd 4530 php5_5.4.44-0+deb7u1.dsc
 86afedeb1bd212603cc5c8f4fa6630b7419da93d 15878182 php5_5.4.44.orig.tar.gz
 81674b968578ce87adb2dad1a6be0e0df6be80fe 147909 php5_5.4.44-0+deb7u1.diff.gz
 15cbe7b3ec2d05213a91e824e4e7875ebaec2888 1024 php5_5.4.44-0+deb7u1_all.deb
 acad6053e72abdd8620b2879c334474a8e10444b 362880 php-pear_5.4.44-0+deb7u1_all.deb
 a9009cd6c6bbf2d3fe2a3e046828522a6af2417b 624754 php5-common_5.4.44-0+deb7u1_amd64.deb
 b44147a3d4494ad326c668355bbcd944c8883176 2709882 libapache2-mod-php5_5.4.44-0+deb7u1_amd64.deb
 6a70031ec0092ffcb43fbec268e6e1579b4e8bcb 2708524 libapache2-mod-php5filter_5.4.44-0+deb7u1_amd64.deb
 548539483ba941d33977a1383a5af27dbb34271d 5177658 php5-cgi_5.4.44-0+deb7u1_amd64.deb
 0466a5d63f0af320f9281b5b348e6d723f434322 2597584 php5-cli_5.4.44-0+deb7u1_amd64.deb
 7f395f6af7b5b9886e6ea5078e312aa73c4a517e 2629772 php5-fpm_5.4.44-0+deb7u1_amd64.deb
 94fcd4de147529931a9402532101cbb097f496c1 2706608 libphp5-embed_5.4.44-0+deb7u1_amd64.deb
 fa87bee3cbe554767431f0e19e4dbea62c1601ac 497596 php5-dev_5.4.44-0+deb7u1_amd64.deb
 f8149922f21164907f363d51b09d2da918a68da5 16129352 php5-dbg_5.4.44-0+deb7u1_amd64.deb
 2b3473b022aa06679fa7ae76b8c5b423aebf66e5 29482 php5-curl_5.4.44-0+deb7u1_amd64.deb
 95f658015bc5a5c86a050c2d5d08c5ca4c5bb2d6 9894 php5-enchant_5.4.44-0+deb7u1_amd64.deb
 e87b8ca5f330b4f216a68a263f7059337f6b1c85 35688 php5-gd_5.4.44-0+deb7u1_amd64.deb
 20864628ac65ada0054351f9cb777a223abdba0b 17006 php5-gmp_5.4.44-0+deb7u1_amd64.deb
 63e39b425d447192961e7a470ab6c97fc259bec3 35582 php5-imap_5.4.44-0+deb7u1_amd64.deb
 8c1286734a30321e1e4a7cd35bcf14d37f1558b3 49576 php5-interbase_5.4.44-0+deb7u1_amd64.deb
 b189fe2a00bd392c139255f6ea4860b52ea6e5a1 72168 php5-intl_5.4.44-0+deb7u1_amd64.deb
 6c2f65bb49b88b6fde66c439090b801503d78adf 23870 php5-ldap_5.4.44-0+deb7u1_amd64.deb
 137c8148935db15cec7ee75ac02e6576fdd1d68f 16098 php5-mcrypt_5.4.44-0+deb7u1_amd64.deb
 6830c127203438c8128be4325073608379bdeb37 80846 php5-mysql_5.4.44-0+deb7u1_amd64.deb
 1d44acfd316c2f9cada36a96415b9d8fc0cb98c0 164458 php5-mysqlnd_5.4.44-0+deb7u1_amd64.deb
 b4630bec27a2fddcbb316caceec674725e4cead6 37062 php5-odbc_5.4.44-0+deb7u1_amd64.deb
 158c616e779fee3a872333b018d41f3570ed1ee9 64600 php5-pgsql_5.4.44-0+deb7u1_amd64.deb
 fde47c506fba7550c6f9499ad6feefb7722cc9b5 8900 php5-pspell_5.4.44-0+deb7u1_amd64.deb
 8269faff9bee61224e40028f0ed6627056bc2348 5194 php5-recode_5.4.44-0+deb7u1_amd64.deb
 89cc91a16a85ca5ea0f78c6772524551cb562ca3 21932 php5-snmp_5.4.44-0+deb7u1_amd64.deb
 7e1f177f5e2ddfc5a032eb73bfc7d305252b306a 30486 php5-sqlite_5.4.44-0+deb7u1_amd64.deb
 31148beb9ec34ea0a1b3194403c6525af4a7f30b 28980 php5-sybase_5.4.44-0+deb7u1_amd64.deb
 5fa01fb6f08dddb13031a7ee84c3666a2a2a2fc7 19650 php5-tidy_5.4.44-0+deb7u1_amd64.deb
 08ccc5d6de1364c295b02af283f1d3711150729c 36334 php5-xmlrpc_5.4.44-0+deb7u1_amd64.deb
 4ac7fd8cca60003d47fc6af9307b0b884636f62b 15466 php5-xsl_5.4.44-0+deb7u1_amd64.deb
Checksums-Sha256: 
 791da63cab9929eab85fdcc06df371c92e9c802e62cf4ace93e97e859dff6eaa 4530 php5_5.4.44-0+deb7u1.dsc
 1799998e48da3d8f34722840628e18789e26ea21741d4e498ade6749b3266602 15878182 php5_5.4.44.orig.tar.gz
 997d9563eb49385e6d276aeec04eb8942f4cf7fd6d6f1cc56f918a34762a3958 147909 php5_5.4.44-0+deb7u1.diff.gz
 994fd5f602fa41c8170d0f556fd5d3e12e66cccba1d174e89e1e6d388273f71d 1024 php5_5.4.44-0+deb7u1_all.deb
 5668f9a54e2b2912fe8320825b425c46597474fb146899f98fe71b3fbf6eabf7 362880 php-pear_5.4.44-0+deb7u1_all.deb
 088db2ade046a38cf42e7f708018de80211847ca83c347338a83bb97ca90290f 624754 php5-common_5.4.44-0+deb7u1_amd64.deb
 bb52026bde4fcda449632f67708128a9c682860515817626b1fd3154d9d625fe 2709882 libapache2-mod-php5_5.4.44-0+deb7u1_amd64.deb
 3a24b4878e5b457b4f9b5c2dd01751deb2add01f3c772adc8efcfb8888166c15 2708524 libapache2-mod-php5filter_5.4.44-0+deb7u1_amd64.deb
 39ebcb690a6fcc67c7baeed9d857611ba188e6d4f25d49d25a2104603b816b13 5177658 php5-cgi_5.4.44-0+deb7u1_amd64.deb
 0762c865016441eece98724577ade485fbce1daecf01f75a38985a97b5757e53 2597584 php5-cli_5.4.44-0+deb7u1_amd64.deb
 5cd9f7b3459e03c6a2f57d44618a7c3a99dbbdefae17d833bb8a972d74d6d79c 2629772 php5-fpm_5.4.44-0+deb7u1_amd64.deb
 4ef63b9218bc1fc402d8135426f0c552d62ccf457a7fd6df1a67337b1a376f1d 2706608 libphp5-embed_5.4.44-0+deb7u1_amd64.deb
 3dbde780d9ce05fc322fd094bcdd861774d399206359fccceb3d9e01a5c56b60 497596 php5-dev_5.4.44-0+deb7u1_amd64.deb
 2e68c435173a62789ceb6715bfa650742df0744066f5761e6903a574b5e4cbf6 16129352 php5-dbg_5.4.44-0+deb7u1_amd64.deb
 d3c6f857d85c1be7b80153315fec9b507e3fd221ec3040c0441b4d4a21468118 29482 php5-curl_5.4.44-0+deb7u1_amd64.deb
 131bc9b82de9f7577d4358bffda9f0436ad328f1ec08dff212abbf961551d19d 9894 php5-enchant_5.4.44-0+deb7u1_amd64.deb
 94f864c119ceb437d553b8640b5f07b8c556c32935de4dd163915cf9f72a1509 35688 php5-gd_5.4.44-0+deb7u1_amd64.deb
 c62c29d431598cf81e7b87b17360678a5e7bc2a1c2fad9f5ea8277096e64764b 17006 php5-gmp_5.4.44-0+deb7u1_amd64.deb
 04a8181941b4e53115b2fb746a4723c912d429a13de456d6e29498bcc1f9f130 35582 php5-imap_5.4.44-0+deb7u1_amd64.deb
 f2f4e3b7b1131de9e11a6bfeb2a9e60826ed02083f61c8131593b02a42710bf7 49576 php5-interbase_5.4.44-0+deb7u1_amd64.deb
 5636641739f1ee4c631136db84e1606f50e09be3989feb619f9d9a524315e2ae 72168 php5-intl_5.4.44-0+deb7u1_amd64.deb
 a50dc2b9af2ce59df4f19043d34b09f4616e5da4ae1c57282d7b2c9aa45e974d 23870 php5-ldap_5.4.44-0+deb7u1_amd64.deb
 c29b410d5ee57147b11824380d7599d2ba30d2413ddb63cd34c453e948d648c7 16098 php5-mcrypt_5.4.44-0+deb7u1_amd64.deb
 7b73c5330ce89a7a284f034a1bccb770f01440f4a952ce643aac36c7f7996583 80846 php5-mysql_5.4.44-0+deb7u1_amd64.deb
 de046ee8b26899eaf2b2ac6cb07aa67a9a144e171260ea1fe4db9d0d08263866 164458 php5-mysqlnd_5.4.44-0+deb7u1_amd64.deb
 db215b86a7b23d6c72cc90563a64666882034579edabfbfda19009ce04669900 37062 php5-odbc_5.4.44-0+deb7u1_amd64.deb
 0ed4226dc1ad2d12d44e1b5cb2fd570020edbcbf141452bcc7d55f716c5d361d 64600 php5-pgsql_5.4.44-0+deb7u1_amd64.deb
 f55db509c1cc9f9256f601ed12eec6961811e54ecb99a5154d54b66a077ae949 8900 php5-pspell_5.4.44-0+deb7u1_amd64.deb
 1b3cbd2532b9b610984137f5516123b722970cb9e706798565da2da6cec476cb 5194 php5-recode_5.4.44-0+deb7u1_amd64.deb
 b22a2b5b5031133bc26e63b5fd1ae2bbb793df089e251c8b6512b314c164b45b 21932 php5-snmp_5.4.44-0+deb7u1_amd64.deb
 88b83a05c2acfecedb5278dae0fb325aead5c8550783314b23c38776273980d1 30486 php5-sqlite_5.4.44-0+deb7u1_amd64.deb
 e6374d4c20dbea0a4e03a20c0464e7ca95d4c8d3aa533576f7e78f594c6d2257 28980 php5-sybase_5.4.44-0+deb7u1_amd64.deb
 4c9949f21136454d210c15ed52e99eec40481c6684724eccc025bb8131aa675e 19650 php5-tidy_5.4.44-0+deb7u1_amd64.deb
 a59e775bc4d28e6eea48dfce6c2dbbfd52abd005fbf01ea777a6b778d8a7930b 36334 php5-xmlrpc_5.4.44-0+deb7u1_amd64.deb
 792fc712e2bb3e0dae32964c7cf3566f7e1dc950b0d839b892137c785ae094e0 15466 php5-xsl_5.4.44-0+deb7u1_amd64.deb
Files: 
 b3c9796525bb266cedf3ebac22585236 4530 php optional php5_5.4.44-0+deb7u1.dsc
 9a6f79bc68eb926d230448905229dd1c 15878182 php optional php5_5.4.44.orig.tar.gz
 dd0c49b51ee1c46c341e41f1c6cd8aa6 147909 php optional php5_5.4.44-0+deb7u1.diff.gz
 c3d3415bd2bb63f5db284d296b2bba39 1024 php optional php5_5.4.44-0+deb7u1_all.deb
 f1c9a6829f28c9ba3afe50e379a62684 362880 php optional php-pear_5.4.44-0+deb7u1_all.deb
 927fde6ab0cc441e03cdf36b4c4d5a9b 624754 php optional php5-common_5.4.44-0+deb7u1_amd64.deb
 43321f4bd495883cb353a29e2cd2fdb6 2709882 httpd optional libapache2-mod-php5_5.4.44-0+deb7u1_amd64.deb
 3528520c49ee6015d0e0bbd3be8cab26 2708524 httpd extra libapache2-mod-php5filter_5.4.44-0+deb7u1_amd64.deb
 a8915faac5df653426144e42b0986e7e 5177658 php optional php5-cgi_5.4.44-0+deb7u1_amd64.deb
 e4b0f14ca6bdcd97248e4eb2abd25ee4 2597584 php optional php5-cli_5.4.44-0+deb7u1_amd64.deb
 33425ac94cf9d5e02984876d1f7ccd07 2629772 php optional php5-fpm_5.4.44-0+deb7u1_amd64.deb
 98b6fd611e749134216e6a7a5cee4486 2706608 php optional libphp5-embed_5.4.44-0+deb7u1_amd64.deb
 22c48be05be38a72c3fdc6e118ba76c9 497596 php optional php5-dev_5.4.44-0+deb7u1_amd64.deb
 9ec4e9d81546dcf3e3284a42fcd7ea5a 16129352 debug extra php5-dbg_5.4.44-0+deb7u1_amd64.deb
 50ff1b99963a80649da2292b2cac437c 29482 php optional php5-curl_5.4.44-0+deb7u1_amd64.deb
 6e444b8a7d006b3d74c634f7b876d7e8 9894 php optional php5-enchant_5.4.44-0+deb7u1_amd64.deb
 3a399856cccdbc51ff7c8ca9e5061b0a 35688 php optional php5-gd_5.4.44-0+deb7u1_amd64.deb
 8d77c2069fe4a41c120f375f3a14a94a 17006 php optional php5-gmp_5.4.44-0+deb7u1_amd64.deb
 6c065b9e36391f7150af87983f1875cd 35582 php optional php5-imap_5.4.44-0+deb7u1_amd64.deb
 3edc989936867a9a7d6d3422a2a4411b 49576 php optional php5-interbase_5.4.44-0+deb7u1_amd64.deb
 025efba32fca87d4f1b17ed4df03cc00 72168 php optional php5-intl_5.4.44-0+deb7u1_amd64.deb
 7b585e18b8b9c33fb945b442c2923cd6 23870 php optional php5-ldap_5.4.44-0+deb7u1_amd64.deb
 504365564f2f5fba8a884cdd6ce8f928 16098 php optional php5-mcrypt_5.4.44-0+deb7u1_amd64.deb
 d61e393a4b301bdfc43c50bccd913360 80846 php optional php5-mysql_5.4.44-0+deb7u1_amd64.deb
 34e0c96455203794a899d898a8ef06df 164458 php extra php5-mysqlnd_5.4.44-0+deb7u1_amd64.deb
 9a34a36392c9c8a6199c3567e6b4e464 37062 php optional php5-odbc_5.4.44-0+deb7u1_amd64.deb
 191dadf6c68fc51953baeaf50d74ba3b 64600 php optional php5-pgsql_5.4.44-0+deb7u1_amd64.deb
 b46680b084d7a1aea03e391e69a2011c 8900 php optional php5-pspell_5.4.44-0+deb7u1_amd64.deb
 ea2e15c8c1e40efff097980bd53ce47d 5194 php optional php5-recode_5.4.44-0+deb7u1_amd64.deb
 94d1d4e2fd1a787b735097340d12c030 21932 php optional php5-snmp_5.4.44-0+deb7u1_amd64.deb
 4320749abe0f6595e090b5174d377084 30486 php optional php5-sqlite_5.4.44-0+deb7u1_amd64.deb
 64e3882dbe5bf84a9e71d8e7f84cde5c 28980 php optional php5-sybase_5.4.44-0+deb7u1_amd64.deb
 047ec559dec6a747f0c9e3e998d8f0c4 19650 php optional php5-tidy_5.4.44-0+deb7u1_amd64.deb
 878d944243c6b3403ae7facffeb0b0bc 36334 php optional php5-xmlrpc_5.4.44-0+deb7u1_amd64.deb
 4b87cdcbb02d4e88caeff2150cb0defa 15466 php optional php5-xsl_5.4.44-0+deb7u1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQJ8BAEBCgBmBQJV3YBEXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQzMEI5MzNEODBGQ0UzRDk4MUEyRDM4RkIw
Qzk5QjcwRUY0RkNCQjA3AAoJEAyZtw70/LsH0fgQAOXoeZr8857TUj29qxhyJSlS
b2HC2Wb9iu2e2blDCSwAZ7mYQHT8Ih2OwQqHKu2dZIfzGyIrJPNzzdlURnWWq7SY
HtApj68rDQQTaTl8vjFa4GoMa5NgqeychCR97k3w1O3wYyquLxWL8qLBxyjhNeT+
1f2v+EpSNbQq0FF7zZ4yWT6B1MPQIKWLz/M+sDM/uaNHYqk31FiyYD3PB8QUckAK
GJsBtL/KPZpbop7H8ekMcU4B6prBVGhEWSDziKqtV99fSulXTdKbd2id0E9tKSON
VDI05w9fQg1XMwaF4hNVRAFQTPaHykZjIzRKvVQ7cqdJkeI33+yxHvmUYUcaQHwL
qjDLF+aGEkA/UhQgfRDjQhu++3u/a4uxfmO21NbMqz3YAiD8cY8KawlTodbGJ67z
jDPmGMnlV44vBWl2GcVxst/fShgrqVQSnVLXV+V8F0ld7gamyoD2/Ja+c2M884FS
M0Dgz6p8w3EawCauWj38nDlphJkb499Yy53Gzirz17NQrsSJbL+a5givCLq5f/mp
uyrGIF+h++lgRpjEkZWpblLWF/Hdnmaga49GkRsTVpfBekX4S/JYUrW+HvxgkG5A
L6L1L68ao+ikUfnmBHmRREbkp6g+G6fSjZzj6IIKcG1dE7MjulQ+PwhOTjeFunA9
QFOkD5DkYpYXoP4VeJ07
=Xuh8
-----END PGP SIGNATURE-----