Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.63885
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1775-1)
Summary:The remote host is missing an update for the Debian 'php-json-ext' package(s) announced via the DSA-1775-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'php-json-ext' package(s) announced via the DSA-1775-1 advisory.

Vulnerability Insight:
It was discovered that php-json-ext, a JSON serialiser for PHP, is prone to a denial of service attack, when receiving a malformed string via the json_decode function.

For the oldstable distribution (etch), this problem has been fixed in version 1.2.1-3.2+etch1.

The stable distribution (lenny) does not contain a separate php-json-ext package, but includes it in the php5 packages, which will be fixed soon.

The testing distribution (squeeze) and the unstable distribution (sid) do not contain a separate php-json-ext package, but include it in the php5 packages.

We recommend that you upgrade your php-json-ext packages.

Affected Software/OS:
'php-json-ext' package(s) on Debian 4.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-1271
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html
Debian Security Information: DSA-1775 (Google Search)
http://www.debian.org/security/2009/dsa-1775
Debian Security Information: DSA-1789 (Google Search)
http://www.debian.org/security/2009/dsa-1789
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html
http://www.mandriva.com/security/advisories?name=MDVSA-2009:090
http://cvs.php.net/viewvc.cgi/php-src/ext/json/JSON_parser.c?r1=1.1.2.14&r2=1.1.2.15
http://www.openwall.com/lists/oss-security/2009/04/01/9
http://www.redhat.com/support/errata/RHSA-2009-0350.html
http://secunia.com/advisories/34770
http://secunia.com/advisories/34830
http://secunia.com/advisories/34933
http://secunia.com/advisories/35003
http://secunia.com/advisories/35007
http://secunia.com/advisories/35306
http://secunia.com/advisories/35685
http://secunia.com/advisories/36701
SuSE Security Announcement: SUSE-SR:2009:012 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
https://usn.ubuntu.com/761-1/
http://www.ubuntu.com/usn/USN-761-2
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.