Univention Bugzilla – Bug 47848
php5: Multiple issues (4.2)
Last modified: 2018-09-26 13:41:47 CEST
New Debian php5 5.6.38+dfsg-0+deb8u1 fixes: This update addresses the following issue: * Cross-site scripting (XSS) flaw in Apache2 component via body of 'Transfer-Encoding: chunked' request (CVE-2018-17082) * Cross-site scripting (XSS) flaw in Apache2 component via body of 'Transfer-Encoding: chunked' request (CVE-2018-17082) * Cross-site scripting (XSS) flaw in Apache2 component via body of 'Transfer-Encoding: chunked' request (CVE-2018-17082)
--- mirror/ftp/4.2/unmaintained/4.2-5/source/php5_5.6.37+dfsg-0+deb8u1.dsc +++ apt/ucs_4.2-0-errata4.2-5/source/php5_5.6.38+dfsg-0+deb8u1.dsc @@ -1,3 +1,10 @@ +5.6.38+dfsg-0+deb8u1 [Wed, 19 Sep 2018 22:05:16 -0400] Roberto C. Sanchez <roberto@debian.org>: + + * Non-maintainer upload by the LTS Team. + * Fix CVE-2018-17082: The Apache2 component allows XSS via the body of a + "Transfer-Encoding: chunked" request because of a defect in request + handling. + 5.6.37+dfsg-0+deb8u1 [Fri, 31 Aug 2018 22:28:51 -0400] Roberto C. Sanchez <roberto@debian.org>: * Non-maintainer upload by the LTS Team. <http://10.200.17.11/4.2-5/#6396900720973904740>
OK: yaml OK: announce_errata OK: patch FAIL: piuparts [4.2-5] 339b4da4b3 Bug #47848: php5 5.6.38+dfsg-0+deb8u1 doc/errata/staging/php5.yaml | 4 ---- 1 file changed, 4 deletions(-) [4.2-5] b20ba33407 Bug #47848: php5 5.6.38+dfsg-0+deb8u1 doc/errata/staging/php5.yaml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+)
<http://errata.software-univention.de/ucs/4.2/521.html>