Bug 190034

Summary: CVE-2006-1990 php multiple issues (CVE-2006-1991)
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: phpAssignee: Joe Orton <jorton>
Status: CLOSED ERRATA QA Contact: David Lawrence <dkl>
Severity: medium Docs Contact:
Priority: medium    
Version: 5Keywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: source=bugtraq,reported=20060424,public=20060424,impact=moderate
Fixed In Version: 5.1.4-1 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-05-17 11:56:32 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2006-04-26 20:30:36 UTC
CVE-2006-1990 php multiple issues (CVE-2006-1991)

CVE-2006-1990 - wordwrap integer overflow
An integer overflow issue was discovered in PHP.  This issue could
potentially lead to arbitrary code execution as it allows overwriting
an arbitrary section of memory with user supplied data.  The
exploitability of this issue will depend on how a user program is
written to accept and process data passed to the wordwrap function.

CVE-2006-1991 - substr_compare DoS
It is possible to cause an OOB memory read via an improperly issued
call to the substr_compare function.  The ability to exploit this
issue will depend on how a user program is written to pass invalid
data to the substr_compare function.

http://www.infigo.hr/en/in_focus/advisories/INFIGO-2006-04-02

This issue also affects FC4

Comment 1 Joe Orton 2006-05-17 11:56:32 UTC
Fixed in FEDORA-2006-289.