| MDVSA-2011:069: php |
|
|
|
| Écrit par Administrator |
| Mardi, 12 Avril 2011 11:00 |
|
It was discovered that the /etc/cron.d/php cron job for php-session
allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php (CVE-2011-0441). Packages for 2009.0 are provided as of the Extended Maintenance Program. Please visit this link to learn more: http://store.mandriva.com/product_info.php?cPath=149&products_id=490 The updated packages contains a fix that corrects this flaw. |



























































