Bug#479723: [php-maint] Bug#479723: Bug#479723: [Secure-testing-team] php 5.2.6 Security Fixes

2008-05-13 Thread sean finney
hiya, On Friday 09 May 2008 09:31:33 am Thijs Kinkhorst wrote: > Next up: php4 in stable. What's the status? i have backported the patches that seem relevant into the php4 etch branch. i've verified that it builds a working /usr/bin/php4 but haven't verified more than that. i guess i can chec

Bug#479723: [php-maint] Bug#479723: Bug#479723: [Secure-testing-team] php 5.2.6 Security Fixes

2008-05-09 Thread Thijs Kinkhorst
Hi Sean, On Thursday 8 May 2008 22:31, sean finney wrote: > anyway, the patches are all in svn now, and they cleanly apply.  i have not > tested the build/update though, and will not have time to do this until > sometime next week most likely.  could someone else pick it up from here? Ok, I've bu

Bug#479723: [php-maint] Bug#479723: [Secure-testing-team] php 5.2.6 Security Fixes

2008-05-08 Thread sean finney
hi everyone (again) sat down and spent some time looking at these: On Wednesday 07 May 2008 11:52:41 pm Kees Cook wrote: > On Tue, May 06, 2008 at 10:16:25AM +, Moritz Naumann wrote: > > * Fixed possible stack buffer overflow in FastCGI SAPI. (Andrei > > Nigmatulin) > > --> CVE-2008

Bug#479723: [php-maint] Bug#479723: [Secure-testing-team] php 5.2.6 Security Fixes

2008-05-07 Thread sean finney
hi everyone, On Wednesday 07 May 2008 11:52:41 pm Kees Cook wrote: > Dustin Kirkland from the Ubuntu Server Team tracked down commits that > map to these issues. and earlier the following url's were forwarded to me by nico: http://www.openwall.com/lists/oss-security/2008/05/02/2 http://www.openw

Bug#479723: [Secure-testing-team] php 5.2.6 Security Fixes

2008-05-07 Thread Kees Cook
Hi, Dustin Kirkland from the Ubuntu Server Team tracked down commits that map to these issues. On Tue, May 06, 2008 at 10:16:25AM +, Moritz Naumann wrote: > * Fixed possible stack buffer overflow in FastCGI SAPI. (Andrei > Nigmatulin) > --> CVE-2008-2050 (acc. to > http://marc.info/