Bug 618825 (CVE-2010-2101, MOPS-2010-041, MOPS-2010-042, MOPS-2010-043, MOPS-2010-044, MOPS-2010-045, MOPS-2010-046)
Summary: | CVE-2010-2101 php: multiple interruption vulnerabilities (MOPS-2010-04[123456]) | ||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> | ||||||||||||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||||||||||||
Status: | CLOSED DUPLICATE | QA Contact: | |||||||||||||||
Severity: | unspecified | Docs Contact: | |||||||||||||||
Priority: | unspecified | ||||||||||||||||
Version: | unspecified | CC: | jorton | ||||||||||||||
Target Milestone: | --- | Keywords: | Security | ||||||||||||||
Target Release: | --- | ||||||||||||||||
Hardware: | All | ||||||||||||||||
OS: | Linux | ||||||||||||||||
Whiteboard: | |||||||||||||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||||||||||||
Doc Text: | Story Points: | --- | |||||||||||||||
Clone Of: | Environment: | ||||||||||||||||
Last Closed: | 2010-07-27 20:12:29 UTC | Type: | --- | ||||||||||||||
Regression: | --- | Mount Type: | --- | ||||||||||||||
Documentation: | --- | CRM: | |||||||||||||||
Verified Versions: | Category: | --- | |||||||||||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||||||||||
Embargoed: | |||||||||||||||||
Attachments: |
|
Description
Tomas Hoger
2010-07-27 20:07:38 UTC
Created attachment 434819 [details]
MOPS-2010-041 reproducer
Created attachment 434820 [details]
MOPS-2010-042 reproducer
Created attachment 434821 [details]
MOPS-2010-043 reproducer
Created attachment 434822 [details]
MOPS-2010-044 reproducer
Created attachment 434823 [details]
MOPS-2010-045 reproducer
Created attachment 434824 [details]
MOPS-2010-046 reproducer
These are similar to CVE-2010-2100 issues, with the same patches addressing these issues too. For details, see bug #618785, comment #6. *** This bug has been marked as a duplicate of bug 618785 *** Statement: Red Hat does not consider interruption issues allowing safe_mode / open_basedir restriction bypass to be security sensitive. For more details see https://bugzilla.redhat.com/show_bug.cgi?id=169857#c1 and http://www.php.net/security-note.php |