Rapid7 Vulnerability & Exploit Database

SUSE Linux Security Vulnerability: CVE-2009-0754

Back to Search

SUSE Linux Security Vulnerability: CVE-2009-0754

Severity
2
CVSS
(AV:L/AC:L/Au:N/C:N/I:P/A:N)
Published
03/03/2009
Created
07/25/2018
Added
02/17/2015
Modified
07/04/2017

Description

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

Solution(s)

  • suse-upgrade-apache2-mod_php5
  • suse-upgrade-php5-bcmath
  • suse-upgrade-php5-bz2
  • suse-upgrade-php5-calendar
  • suse-upgrade-php5-ctype
  • suse-upgrade-php5-curl
  • suse-upgrade-php5-dba
  • suse-upgrade-php5-dbase
  • suse-upgrade-php5-devel
  • suse-upgrade-php5-dom
  • suse-upgrade-php5-exif
  • suse-upgrade-php5-fastcgi
  • suse-upgrade-php5-ftp
  • suse-upgrade-php5-gd
  • suse-upgrade-php5-gettext
  • suse-upgrade-php5-gmp
  • suse-upgrade-php5-hash
  • suse-upgrade-php5-iconv
  • suse-upgrade-php5-imap
  • suse-upgrade-php5-json
  • suse-upgrade-php5-ldap
  • suse-upgrade-php5-mbstring
  • suse-upgrade-php5-mcrypt
  • suse-upgrade-php5-mhash
  • suse-upgrade-php5-mysql
  • suse-upgrade-php5-ncurses
  • suse-upgrade-php5-odbc
  • suse-upgrade-php5-openssl
  • suse-upgrade-php5-pcntl
  • suse-upgrade-php5-pdo
  • suse-upgrade-php5-pear
  • suse-upgrade-php5-pgsql
  • suse-upgrade-php5-posix
  • suse-upgrade-php5-pspell
  • suse-upgrade-php5-readline
  • suse-upgrade-php5-shmop
  • suse-upgrade-php5-snmp
  • suse-upgrade-php5-soap
  • suse-upgrade-php5-sockets
  • suse-upgrade-php5-sqlite
  • suse-upgrade-php5-suhosin
  • suse-upgrade-php5-sysvmsg
  • suse-upgrade-php5-sysvsem
  • suse-upgrade-php5-sysvshm
  • suse-upgrade-php5-tidy
  • suse-upgrade-php5-tokenizer
  • suse-upgrade-php5-wddx
  • suse-upgrade-php5-xmlreader
  • suse-upgrade-php5-xmlrpc
  • suse-upgrade-php5-xmlwriter
  • suse-upgrade-php5-xsl
  • suse-upgrade-php5-zip
  • suse-upgrade-php5-zlib

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;