OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[Security Announce] [ MDKA-2007:027 ] - Updated php-session packages address session removal error

securitymandriva.com
Date: Mon Apr 23 2007 - 15:48:34 CDT


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 _______________________________________________________________________
 
 Mandriva Linux Advisory MDKA-2007:027
 http://www.mandriva.com/security/
 _______________________________________________________________________
 
 Package : php-session
 Date : April 23, 2007
 Affected: 2007.0
 _______________________________________________________________________
 
 Problem Description:
 
 The php-session package includes a cron setting to remove PHP sessions
 that are no longer in use. Previously, it could expire the session
 even if it was still in use. This update will prevent the cron job
 from removing sessions that are still actively being used, and will
 only expire after the last action done in the session is older than
 the number of minutes defined in /var/lib/php/maxlifetime.
 _______________________________________________________________________

 Updated Packages:
 
 Mandriva Linux 2007.0:
 bf5539880a739f22230626648d7f9a48 2007.0/i586/php-session-5.1.6-1.2mdv2007.0.i586.rpm
 d10886ad6d4891459882b82674b6db83 2007.0/SRPMS/php-session-5.1.6-1.2mdv2007.0.src.rpm

 Mandriva Linux 2007.0/X86_64:
 aeccbbd8c2b216c4c2928333b4582779 2007.0/x86_64/php-session-5.1.6-1.2mdv2007.0.x86_64.rpm
 d10886ad6d4891459882b82674b6db83 2007.0/SRPMS/php-session-5.1.6-1.2mdv2007.0.src.rpm
 _______________________________________________________________________

 To upgrade automatically use MandrivaUpdate or urpmi. The verification
 of md5 checksums and GPG signatures is performed automatically for you.

 All packages are signed by Mandriva for security. You can obtain the
 GPG public key of the Mandriva Security Team by executing:

  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

 You can view other update advisories for Mandriva Linux at:

  http://www.mandriva.com/security/advisories

 If you want to report vulnerabilities, please contact

  security_(at)_mandriva.com
 _______________________________________________________________________

 Type Bits/KeyID Date User ID
 pub 1024D/22458A98 2000-07-10 Mandriva Security Team
  <security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iD8DBQFGLPFQmqjQ0CJFipgRApwzAKC/uBXCSY44b9uThoC4BLNSLW+UPACgvV+p
9+0OHRZ8XcsxX5XmNGhl5pE=
=MIaS
-----END PGP SIGNATURE-----

------------=_1177361576-8862-4591
Content-Type: text/plain; name="message-footer.txt"
Content-Disposition: inline; filename="message-footer.txt"
Content-Transfer-Encoding: 8bit

To unsubscribe, send a email to sympamandrivalinux.org
with this subject : unsubscribe security-announce
_______________________________________________________
Want to buy your Pack or Services from Mandriva?
Go to http://www.mandrivastore.com
Join the Club : http://www.mandrivaclub.com
_______________________________________________________

------------=_1177361576-8862-4591--