Book Mark

Ike.ninja

Linux Fun
  • Home
  • How to
  • Reference Links
  • Categories
    • Releases
    • Plesk
    • Community
    • CMS
    • security
    • MYSQL
    • cPanel
  • Tools
    • IP Checker
    • Byte Converter
RSS

Security Advisory 2013-08-20

Aug21
by Ike on August 21, 2013 at 1:48 pm
Posted In: Community, cPanel, Hosting, News, security

SUMMARY

The PHP development team announces the immediate availability of PHP 5.4.18. About 30 bugs were fixed, including security issues CVE-2013-4113 and CVE-2013-4248. All users of PHP are encouraged to upgrade to this release. cPanel has released EasyApache 3.22.5 with this updated version of PHP 5.4.18 to address this issue.

AFFECTED VERSIONS

All versions of PHP5 before 5.4.18

SECURITY RATING

The National Vulnerability Database (NIST) has given the following severity rating of these CVEs:
CVE-2013-4113 — MEDIUM
CVE-2013-4248 — MEDIUM

PHP 5.4.18

CVE-2013-4113: ext/xml/xml.c in PHP before 5.3.27 (also 5.4.x) does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibility have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

CVE-2013-4248: The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a “character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attacks to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

SOLUTION

cPanel, Inc. has released EasyApache 3.22.5 with updated version PHP5.4 to correct these issues. To update, please rebuild your EasyApache profile. For more information on rebuilding profiles, please consult our documentation (http://go.cpanel.net/ea).
Unless EasyApache updates are disabled on your system, the latest version of EasyApache will be used whenever EasyApache is run. Note that EasyApache updates must be done manually.

REFERENCES

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4248
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4113
http://www.php.net/ChangeLog-5.php#5.4.18
http://php.net/archive/2013.php#id2013-08-15-1

For the PGP signed message, please go here.

└ Tags: cPanel, CVE, news, PHP, security
 Comment 

Ubuntu: 1929-1: Linux kernel vulnerability

Aug20
by Ike on August 20, 2013 at 11:58 pm
Posted In: Other

(Aug 20) The system could be made to expose sensitive information.

└ Tags: Linux, sensitive, vulnerability
 Comment 

Ubuntu: 1935-1: Linux kernel vulnerabilities

Aug20
by Ike on August 20, 2013 at 11:58 pm
Posted In: Other

(Aug 20) Several security issues were fixed in the kernel.

└ Tags: Linux
 Comment 

Ubuntu: 1928-1: Puppet vulnerabilities

Aug19
by Ike on August 19, 2013 at 11:56 pm
Posted In: Other

(Aug 15) Several security issues were fixed in Puppet.

 Comment 

Debian: 2738-1: ruby1.9.1: Multiple vulnerabilities

Aug19
by Ike on August 19, 2013 at 11:27 pm
Posted In: Other

(Aug 18) Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may lead to denial of service and other security problems. The Common Vulnerabilities and Exposures project identifies the following problems: [More…]

└ Tags: Ruby, security
 Comment 
  • Page 2,600 of 2,972
  • « First
  • «
  • 2,598
  • 2,599
  • 2,600
  • 2,601
  • 2,602
  • »
  • Last »

What’s New?

  • Debian: Important DoS Vulnerabilities in FFmpeg DSA-6080-1 Advisory
  • Ubuntu 20.04 LTS: USN-7922-1 Linux Kernel Important Security Issues
  • Ubuntu 24.04 LTS: Kernel Important Security Fixes USN-7921-1 CVE-2025-39946
  • Debian: firefox-esr Critical Privilege Escalation DSA-6078-1 CVE-2025-14321
  • 2026 Global Partner Program Announcement
  • Fedora 43: python3-docs Update 2025-e235793f10 – Maintenance Release
  • Fedora 43: python3.14 Critical Update Addresses Quadratic Complexity Bug
  • Debian: WordPress Important XSS and Info Disclosure DSA-6075-1
  • Ubuntu 22.04 LTS: fontTools Important Path Traversal Risk CVE-2025-66034
  • Debian: webkit2gtk Critical Info Exfiltration DSA-6074-1 CVE-2025-13947
  • Ubuntu 25.10: Radare2 Critical Memory Leak Security Advisory USN-7915-1
  • Fedora 41 ABRT Critical Command Injection Vulnerability Fix CVE-2025-12744
  • Fedora 42: mingw-libpng Important Heap Buffer Overflow Vuln 2025-9d0f04f316
  • Ubuntu: WebKitGTK High Remote Code Execution Threat USN-7914-1
  • Debian Trixie: FFmpeg Critical Denial of Service and Code Exec DSA-6073-1
  • Fedora 42: tinygltf Update 2.9.7 Advisory FEDORA-2025-ac8ed4a110
  • Fedora 43: webkitgtk Critical Update for CVE-2025-13947, 43458, 66287
  • Fedora 43: TinyGLTF 2.9.7 Security Advisory FEDORA-2025-47bff6f74d
  • Fedora 42: abrt Critical Command Injection Vulnerability CVE-2025-12744
  • Fedora 42: Chromium High CVE-2025-13630, 13631, 13632 Advisory
  • Fedora 42: cef High Type Confusion Vuln CVE-2025-13223,13224 Advisory
  • Fedora 43: chromium High CVE-2025-13630 Type Confusion and more
  • Fedora 43: abrt Critical Command Injection Fix CVE-2025-12744
  • Ubuntu 22.04: Linux Kernel Azure Important Security Flaws USN-7910-2
  • Ubuntu 22.04: Important Linux Kernel Updates Addressing Security Flaws

Search

Translator

Tags

Business and industry code Community cPanel CVE Debian Debian Linux Distribution - Security Advisories Development Events Fedora Fedora Linux Distribution - Security Advisories General Hosting Important Advisory Linux Moderate Advisory Month in WordPress news Parallels Plesk Parallels Plesk Panel Performance PHP Plesk news and announcements Plesk Panel Podcast ProdDevSec Product and technology Products Project Release News Red Hat Red Hat Linux Distribution - Security Advisories Releases security Security Centre sensitive site Ubuntu Ubuntu Linux Distribution - Security Advisories update updates Various vulnerability Web Server Survey Wordpress wp-briefing

Posts

Helpful Links

  • Liquidweb.com
  • MYSQL Dev Documentation
  • Plugins
  • Source forge SED command
  • Themes
  • WordPress Documentation
  • You Tube
December 2025
M T W T F S S
« Nov    
1234567
891011121314
15161718192021
22232425262728
293031  
  • Google
  • Yahoo
  • Liquid Web
  • Storm
  • YouTube

©1999-2025 Ike.ninja | Powered by WordPress with Easel | Subscribe: RSS | Back to Top ↑

50 queries. 8.75 mb Memory usage. 0.288 seconds.