Debian LTS Essential and Critical Security Patch Updates - Page 137

Find the information you need for your favorite open source distribution .

Debian LTS: DLA-1069-1: tenshi security update


Tenshi creates a file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for modification before a root script executes a "kill `cat /pathname/`" command.

Debian LTS: DLA-1066-1: php5 security update


A stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_parser.c could cause a denial of service or potentially allow executing code. NOTE: this is only relevant for PHP applications that accept untrusted input (instead of the system's php.ini file) for the parse_ini_string