| 1 |
Month of PHP security May 2010 status file
|
| 2 |
|
| 3 |
001: CVE-2007-1581; Only triggerable by malicious script
|
| 4 |
002: External app not in Debian: Campsite
|
| 5 |
003: CVE-2010-1866; Should be fixed for Squeeze, doesn't affect Lenny (5.3 only)
|
| 6 |
004: External app not in Debian: ClanSphere
|
| 7 |
005: External app not in Debian: ClanSphere
|
| 8 |
006: CVE-2010-1864; Only triggerable by malicious script
|
| 9 |
007: External app not in Debian: ClanTiger
|
| 10 |
008: CVE-2010-1862; Only triggerable by malicious script
|
| 11 |
009: CVE-2010-1861; Only triggerable by malicious script
|
| 12 |
010: CVE-2010-1860; Only triggerable by malicious script
|
| 13 |
011: External app not in Debian: DeluxeBB
|
| 14 |
012: CVE-2010-1868; Only triggerable by malicious script
|
| 15 |
013: CVE-2010-1868; Only triggerable by malicious script
|
| 16 |
014: CVE-2010-1914; Only triggerable by malicious script
|
| 17 |
015: CVE-2010-1914; Only triggerable by malicious script
|
| 18 |
016: CVE-2010-1914; Only triggerable by malicious script
|
| 19 |
017: CVE-2010-1915; Only triggerable by malicious script
|
| 20 |
018: External app not in Debian: EFront
|
| 21 |
019: CVE-2010-1916; Serendipity, doesn't affect Lenny (1.4 onwards), pinged Thijs
|
| 22 |
020: CVE-2010-1916; External app; xinha, Just an ITP: #479708, there are embedders
|
| 23 |
021: CVE-2010-1917; PHP fnmatch() Stack Exhaustion Vulnerability
|
| 24 |
022: no CVE yet; Only triggerable by malicious script
|
| 25 |
023: no CVE yet; Cacti, pinged Sean Finney
|
| 26 |
024: no CVE yet; Doesn't affect Lenny, extension is new enough not to have (code) users other than PEAR
|
| 27 |
025: no CVE yet; Doesn't affect Lenny, extension is new enough not to have (code) users other than PEAR
|
| 28 |
026: no CVE yet; Doesn't affect Lenny, extension is new enough not to have (code) users other than PEAR
|
| 29 |
027: no CVE yet; Doesn't affect Lenny, extension is new enough not to have (code) users other than PEAR
|
| 30 |
028: no CVE yet; Doesn't affect Lenny, extension is new enough not to have (code) users other than PEAR
|
| 31 |
029: External app not in Debian: CMSQLITE
|
| 32 |
030: External app not in Debian: CMSQLITE
|
| 33 |
031: External app not in Debian: e107
|
| 34 |
032: no CVE yet; Only triggerable by malicious script
|
| 35 |
033: no CVE yet; Only triggerable by malicious script
|
| 36 |
034: no CVE yet; Only triggerable by malicious script
|
| 37 |
035: External app not in Debian: e107
|