DSA-1938-1

NameDSA-1938-1
SourceDebian
Descriptionphp-mail - insufficient input sanitising
ReferencesCVE-2009-4023, CVE-2009-4111
Debian/oldstablepackage php-mail is fixed in oldstable-security.
Debian/stablenot vulnerable
Debian/testingnot known to be vulnerable
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-mail (PTS)etch1.1.6-2vulnerable
etch (security)1.1.6-2+etch1fixed
lenny, lenny (security)1.1.14-1+lenny1fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
php-mailetch1.1.6-2vulnerableall
etch (security)1.1.6-2+etch1fixedall
lenny, lenny (security)1.1.14-1+lenny1fixedall

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php-mailsourceetch1.1.6-2+etch1unknown
php-mailsourcelenny1.1.14-1+lenny1unknown

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint