Rapid7 Vulnerability & Exploit Database

SUSE Linux Security Advisory: SUSE-SR:2008:014

Back to Search

SUSE Linux Security Advisory: SUSE-SR:2008:014

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
05/05/2008
Created
07/25/2018
Added
12/12/2013
Modified
07/04/2017

Description

The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."

Solution(s)

  • suse-upgrade-apache2-mod_php5
  • suse-upgrade-courier-authlib
  • suse-upgrade-courier-authlib-devel
  • suse-upgrade-courier-authlib-ldap
  • suse-upgrade-courier-authlib-mysql
  • suse-upgrade-courier-authlib-pgsql
  • suse-upgrade-courier-authlib-pipe
  • suse-upgrade-courier-authlib-userdb
  • suse-upgrade-freetype2
  • suse-upgrade-freetype2-32bit
  • suse-upgrade-freetype2-64bit
  • suse-upgrade-freetype2-devel
  • suse-upgrade-freetype2-devel-32bit
  • suse-upgrade-freetype2-devel-64bit
  • suse-upgrade-freetype2-x86
  • suse-upgrade-gnome-screensaver
  • suse-upgrade-graphicsmagick
  • suse-upgrade-graphicsmagick-c
  • suse-upgrade-graphicsmagick-c-devel
  • suse-upgrade-graphicsmagick-devel
  • suse-upgrade-imagemagick
  • suse-upgrade-imagemagick-devel
  • suse-upgrade-imagemagick-extra
  • suse-upgrade-imagemagick-magick
  • suse-upgrade-imagemagick-magick-devel
  • suse-upgrade-libgraphicsmagick-1
  • suse-upgrade-libgraphicsmagick-devel
  • suse-upgrade-libgraphicsmagick1
  • suse-upgrade-libgraphicsmagickwand0
  • suse-upgrade-libmagick-10
  • suse-upgrade-libmagick-devel
  • suse-upgrade-libmagick10
  • suse-upgrade-libwand10
  • suse-upgrade-mtr
  • suse-upgrade-mtr-gtk
  • suse-upgrade-pcre
  • suse-upgrade-pcre-32bit
  • suse-upgrade-pcre-64bit
  • suse-upgrade-pcre-devel
  • suse-upgrade-perl-graphicsmagick
  • suse-upgrade-perl-perlmagick
  • suse-upgrade-php5-bcmath
  • suse-upgrade-php5-bz2
  • suse-upgrade-php5-calendar
  • suse-upgrade-php5-ctype
  • suse-upgrade-php5-curl
  • suse-upgrade-php5-dba
  • suse-upgrade-php5-dbase
  • suse-upgrade-php5-devel
  • suse-upgrade-php5-dom
  • suse-upgrade-php5-exif
  • suse-upgrade-php5-fastcgi
  • suse-upgrade-php5-ftp
  • suse-upgrade-php5-gd
  • suse-upgrade-php5-gettext
  • suse-upgrade-php5-gmp
  • suse-upgrade-php5-hash
  • suse-upgrade-php5-iconv
  • suse-upgrade-php5-imap
  • suse-upgrade-php5-json
  • suse-upgrade-php5-ldap
  • suse-upgrade-php5-mbstring
  • suse-upgrade-php5-mcrypt
  • suse-upgrade-php5-mhash
  • suse-upgrade-php5-mysql
  • suse-upgrade-php5-ncurses
  • suse-upgrade-php5-odbc
  • suse-upgrade-php5-openssl
  • suse-upgrade-php5-pcntl
  • suse-upgrade-php5-pdo
  • suse-upgrade-php5-pear
  • suse-upgrade-php5-pgsql
  • suse-upgrade-php5-posix
  • suse-upgrade-php5-pspell
  • suse-upgrade-php5-readline
  • suse-upgrade-php5-shmop
  • suse-upgrade-php5-snmp
  • suse-upgrade-php5-soap
  • suse-upgrade-php5-sockets
  • suse-upgrade-php5-sqlite
  • suse-upgrade-php5-suhosin
  • suse-upgrade-php5-sysvmsg
  • suse-upgrade-php5-sysvsem
  • suse-upgrade-php5-sysvshm
  • suse-upgrade-php5-tidy
  • suse-upgrade-php5-tokenizer
  • suse-upgrade-php5-wddx
  • suse-upgrade-php5-xmlreader
  • suse-upgrade-php5-xmlrpc
  • suse-upgrade-php5-xmlwriter
  • suse-upgrade-php5-xsl
  • suse-upgrade-php5-zip
  • suse-upgrade-php5-zlib
  • suse-upgrade-squid
  • suse-upgrade-suse-release
  • suse-upgrade-tomcat55
  • suse-upgrade-tomcat55-admin-webapps
  • suse-upgrade-tomcat55-common-lib
  • suse-upgrade-tomcat55-jasper
  • suse-upgrade-tomcat55-jasper-javadoc
  • suse-upgrade-tomcat55-jsp-2_0-api
  • suse-upgrade-tomcat55-jsp-2_0-api-javadoc
  • suse-upgrade-tomcat55-server-lib
  • suse-upgrade-tomcat55-servlet-2_4-api
  • suse-upgrade-tomcat55-servlet-2_4-api-javadoc
  • suse-upgrade-tomcat55-webapps
  • suse-upgrade-tomcat6
  • suse-upgrade-tomcat6-admin-webapps
  • suse-upgrade-tomcat6-docs-webapp
  • suse-upgrade-tomcat6-javadoc
  • suse-upgrade-tomcat6-jsp-2_1-api
  • suse-upgrade-tomcat6-lib
  • suse-upgrade-tomcat6-servlet-2_5-api
  • suse-upgrade-tomcat6-webapps

References

  • suse-upgrade-apache2-mod_php5
  • suse-upgrade-courier-authlib
  • suse-upgrade-courier-authlib-devel
  • suse-upgrade-courier-authlib-ldap
  • suse-upgrade-courier-authlib-mysql
  • suse-upgrade-courier-authlib-pgsql
  • suse-upgrade-courier-authlib-pipe
  • suse-upgrade-courier-authlib-userdb
  • suse-upgrade-freetype2
  • suse-upgrade-freetype2-32bit
  • suse-upgrade-freetype2-64bit
  • suse-upgrade-freetype2-devel
  • suse-upgrade-freetype2-devel-32bit
  • suse-upgrade-freetype2-devel-64bit
  • suse-upgrade-freetype2-x86
  • suse-upgrade-gnome-screensaver
  • suse-upgrade-graphicsmagick
  • suse-upgrade-graphicsmagick-c
  • suse-upgrade-graphicsmagick-c-devel
  • suse-upgrade-graphicsmagick-devel
  • suse-upgrade-imagemagick
  • suse-upgrade-imagemagick-devel
  • suse-upgrade-imagemagick-extra
  • suse-upgrade-imagemagick-magick
  • suse-upgrade-imagemagick-magick-devel
  • suse-upgrade-libgraphicsmagick-1
  • suse-upgrade-libgraphicsmagick-devel
  • suse-upgrade-libgraphicsmagick1
  • suse-upgrade-libgraphicsmagickwand0
  • suse-upgrade-libmagick-10
  • suse-upgrade-libmagick-devel
  • suse-upgrade-libmagick10
  • suse-upgrade-libwand10
  • suse-upgrade-mtr
  • suse-upgrade-mtr-gtk
  • suse-upgrade-pcre
  • suse-upgrade-pcre-32bit
  • suse-upgrade-pcre-64bit
  • suse-upgrade-pcre-devel
  • suse-upgrade-perl-graphicsmagick
  • suse-upgrade-perl-perlmagick
  • suse-upgrade-php5-bcmath
  • suse-upgrade-php5-bz2
  • suse-upgrade-php5-calendar
  • suse-upgrade-php5-ctype
  • suse-upgrade-php5-curl
  • suse-upgrade-php5-dba
  • suse-upgrade-php5-dbase
  • suse-upgrade-php5-devel
  • suse-upgrade-php5-dom
  • suse-upgrade-php5-exif
  • suse-upgrade-php5-fastcgi
  • suse-upgrade-php5-ftp
  • suse-upgrade-php5-gd
  • suse-upgrade-php5-gettext
  • suse-upgrade-php5-gmp
  • suse-upgrade-php5-hash
  • suse-upgrade-php5-iconv
  • suse-upgrade-php5-imap
  • suse-upgrade-php5-json
  • suse-upgrade-php5-ldap
  • suse-upgrade-php5-mbstring
  • suse-upgrade-php5-mcrypt
  • suse-upgrade-php5-mhash
  • suse-upgrade-php5-mysql
  • suse-upgrade-php5-ncurses
  • suse-upgrade-php5-odbc
  • suse-upgrade-php5-openssl
  • suse-upgrade-php5-pcntl
  • suse-upgrade-php5-pdo
  • suse-upgrade-php5-pear
  • suse-upgrade-php5-pgsql
  • suse-upgrade-php5-posix
  • suse-upgrade-php5-pspell
  • suse-upgrade-php5-readline
  • suse-upgrade-php5-shmop
  • suse-upgrade-php5-snmp
  • suse-upgrade-php5-soap
  • suse-upgrade-php5-sockets
  • suse-upgrade-php5-sqlite
  • suse-upgrade-php5-suhosin
  • suse-upgrade-php5-sysvmsg
  • suse-upgrade-php5-sysvsem
  • suse-upgrade-php5-sysvshm
  • suse-upgrade-php5-tidy
  • suse-upgrade-php5-tokenizer
  • suse-upgrade-php5-wddx
  • suse-upgrade-php5-xmlreader
  • suse-upgrade-php5-xmlrpc
  • suse-upgrade-php5-xmlwriter
  • suse-upgrade-php5-xsl
  • suse-upgrade-php5-zip
  • suse-upgrade-php5-zlib
  • suse-upgrade-squid
  • suse-upgrade-suse-release
  • suse-upgrade-tomcat55
  • suse-upgrade-tomcat55-admin-webapps
  • suse-upgrade-tomcat55-common-lib
  • suse-upgrade-tomcat55-jasper
  • suse-upgrade-tomcat55-jasper-javadoc
  • suse-upgrade-tomcat55-jsp-2_0-api
  • suse-upgrade-tomcat55-jsp-2_0-api-javadoc
  • suse-upgrade-tomcat55-server-lib
  • suse-upgrade-tomcat55-servlet-2_4-api
  • suse-upgrade-tomcat55-servlet-2_4-api-javadoc
  • suse-upgrade-tomcat55-webapps
  • suse-upgrade-tomcat6
  • suse-upgrade-tomcat6-admin-webapps
  • suse-upgrade-tomcat6-docs-webapp
  • suse-upgrade-tomcat6-javadoc
  • suse-upgrade-tomcat6-jsp-2_1-api
  • suse-upgrade-tomcat6-lib
  • suse-upgrade-tomcat6-servlet-2_5-api
  • suse-upgrade-tomcat6-webapps

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;