|
|
|
|
| |
Credit:
The original article can be found at: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02247738
|
| |
Vulnerable Systems:
* HP-UX B.11.11 running Apache with PHP v5.2.6 or earlier.
* HP-UX B.11.23 running Apache with PHP v5.2.6 or earlier.
* HP-UX B.11.31 running Apache with PHP v5.2.6 or earlier.
Potential security vulnerabilities have been identified with HP-UX running Apache with PHP. These vulnerabilities could be exploited remotely to create a Denial of Service gain unauthorized access, and perform cross site scripting.
Patch Availability:
HP has provided the following software updates to resolve the vulnerabilities.
Note: Both HP-UX Web Server Suite Version v2.31 and HP-UX Web Server Suite Version v3.10 include PHP v5.2.13.
The updates are available for download from
http://software.hp.com
CVE Information:
CVE-2009-2687
CVE-2009-3291
CVE-2009-3292
CVE-2009-3293
CVE-2009-3557
CVE-2009-4017
CVE-2009-4018
CVE-2009-4142
CVE-2009-4143
Disclosure Timeline:
2010-06-16: Release Date
2010-06-16: Last Updated
|
|
|
|
|