oss-sec mailing list archives

Re: CVE Request (PHP)


From: "Steven M. Christey" <coley () linus mitre org>
Date: Fri, 2 May 2008 11:50:48 -0400 (EDT)



On Fri, 2 May 2008, Josh Bressers wrote:

* Fixed possible stack buffer overflow in the FastCGI SAPI identified by
  Andrei Nigmatulin.

Use CVE-2008-2050

* Properly address incomplete multibyte chars inside escapeshellcmd()
  identified by Stefan Esser.

Use CVE-2008-2051

These will beupdated later.

- Steve


Current thread: