CVE.RADIO
FREN

CVE-2008-3660

phpVulnerabilityPatched

No public exploitation has been reported so far. A fixed version is available (see the table below).

Recommended action: Update to the fixed version listed for your distribution using the native package manager.

Affected & fixed versions by distribution

Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.

DistributionPackageAffectedFixed versionStatus
Red Hat:enterprise_linux:3::asphp-0:4.3.2-51.entfixed
Red Hat:enterprise_linux:3::desktopphp-0:4.3.2-51.entfixed
Red Hat:enterprise_linux:3::esphp-0:4.3.2-51.entfixed
Red Hat:enterprise_linux:3::wsphp-0:4.3.2-51.entfixed
Red Hat:enterprise_linux:4::asphp-0:4.3.9-3.22.15fixed
Red Hat:enterprise_linux:4::desktopphp-0:4.3.9-3.22.15fixed
Red Hat:enterprise_linux:4::esphp-0:4.3.9-3.22.15fixed
Red Hat:enterprise_linux:4::wsphp-0:4.3.9-3.22.15fixed
Red Hat:enterprise_linux:5::client_workstationphp-0:5.1.6-23.2.el5_3fixed
Red Hat:enterprise_linux:5::serverphp-0:5.1.6-23.2.el5_3fixed
Red Hat:rhel_application_stack:2php-0:5.2.6-4.el5s2fixed

Sources