[imp] PHP security

Robert Marchand robert.marchand@UMontreal.CA
Thu, 28 Feb 2002 11:17:40 -0500 (EST)


Hi,

   I have a problem updating the rpms:

# rpm -U -v php-4.1.0-0horde4.i386.rpm
error: failed dependencies:
        libjs.so   is needed by php-4.1.0-0horde4
        libsablot.so.0   is needed by php-4.1.0-0horde4
        php = 4.1.0-0horde2 is needed by php-imap-4.1.0-0horde2
        php = 4.1.0-0horde2 is needed by php-ldap-4.1.0-0horde2
        php = 4.1.0-0horde2 is needed by php-manual-4.1.0-0horde2
        php = 4.1.0-0horde2 is needed by php-mcal-4.1.0-0horde2
        php = 4.1.0-0horde2 is needed by php-mysql-4.1.0-0horde2
        php = 4.1.0-0horde2 is needed by php-odbc-4.1.0-0horde2
        php = 4.1.0-0horde2 is needed by php-pgsql-4.1.0-0horde2

It is the 'libjs.so' and 'libsablot.so.0'.  Where do they come from?
I'm on redhat 7.2.

Thanks.

En réponse à "Brent J. Nordquist" <bjn@horde.org>:

> On Wed, 27 Feb 2002, Jan Schneider <jan@horde.org> wrote:
> 
> > Zitat von "Donatas V." <vyzard@yahoo.com>:
> > 
> > > http://security.e-matters.de/advisories/012002.html
> > 
> > Of course IMP just uses the PHP functionality for handling file
> uploads.
> > So everyone using any PHP application that incorporates file uploads
> > (like IMP) should update to be on the safe side.
> 
> I've updated the Horde-custom PHP 4.1.0 RPMs to add the patch. 
> (Quickly
> regression-tested with RH 7.1 and 7.2 to ensure upload still works
> during
> a compose in IMP.)
> 
> -- 
> Brent J. Nordquist <bjn@horde.org> N0BJN       / OPN: #horde
> Yahoo!: Brent_Nordquist / AIM: BrentJNordquist / ICQ: 76158942
> 
> 
> -- 
> IMP mailing list: http://horde.org/imp/
> Archive: http://marc.theaimsgroup.com/?l=imp&r=1&w=2
> Frequently Asked Questions: http://horde.org/faq/
> To unsubscribe, mail: imp-unsubscribe@lists.horde.org
> 



-----------------
Robert Marchand
DGTIC/SIT
poste 5210