Bug#609315: php5: Upstream bug CVE-2010-4645 / bug #53632, critical: conversion string>double might hang PHP interpreter

2011-01-08 Thread Jort Koopmans
On Sat, 2011-01-08 at 16:31 +0100, Julien Cristau wrote: [..] > Did you actually reproduce this with php 5.2.6.dfsg.1-1+lenny9? AFAIK > people tried and couldn't. As mentioned in my update I couldnt reproduce it, but the 64bit build of php5 seems unaffected, so maybe users with a 32bit install sh

Bug#609315: Upstream bug CVE-2010-4645 / bug #53632, critical: conversion string>double might hang PHP interpreter

2011-01-08 Thread Jort Koopmans
Update: My x64 testsystem running php5.2.6dfsg.1-1+lenny9 does not seem to be affected when using this script from CLI: http://www.php.net/distributions/test_bug53632.txt but php -v shows: /# php -v PHP 5.3.3-6 with Suhosin-Patch (cli) (built: Dec 7 2010 12:47:03) Copyright (c) 1997-2009 The P

Bug#609315: php5: Upstream bug CVE-2010-4645 / bug #53632, critical: conversion string>double might hang PHP interpreter

2011-01-08 Thread Jort Koopmans
Package: php5 Version: 5.2.6.dfsg.1-1+lenny9 Severity: critical >From upstream; http://bugs.php.net/bug.php?id=53632 followed by release 5.3.5 and 5.2.17: http://www.php.net/archive/2011.php#id2011-01-06-1 Short description; Conversions from string to double might cause the PHP interpreter to