Risk: Medium
An iDEFENSE researcher discovered two problems in the image processing functions of PHP (a server-side, HTML-embedded scripting language) of which one is present in woody as well. When reading a JPEG image, PHP can be tricked into an endless loop due to insufficient input validation.
- For the stable distribution (woody) this problem has been fixed in version 4.1.2-7.woody4.
- For the testing distribution (sarge) these problems have been fixed in version 4.3.10-10.
- For the unstable distribution (sid) these problems have been fixed in version 4.3.10-10.
The upgrade of your php4 packages is recommended.
Please note, Debian might not be the only distributor affected by this flaw - it is the one we are currently aware of.