943,350 Members | Top Members by Rank

0

Gentoo Linux PHP Security Advisory

by on May 27th, 2007, 7:50 pm
Gentoo has issued a security advisory with a high impact rating affecting users of PHP <5.2.2.

Several vulnerabilities have been found in PHP, not least a huge number discovered by Stefan Esser during the infamous Month Of PHP Bugs (MOPB) including integer overflows in wbmp.c from the GD library and in the substr_compare() PHP 5 function.

There have also been reports of a buffer overflow in the make_http_soap_request() and in the user_filter_factory_create() functions as well as a buffer overflow in the bundled XMLRPC library. If that weren’t enough, the session_regenerate_id() and the array_user_key_compare() functions contain a double-free vulnerability. Oh, and let’s not forget the implementation errors in the Zend engine, in the mb_parse_str(), the unserialize() and the mail() functions and other elements.

The fact that remote attackers therefore have the potential ability to exploit these vulnerabilities in PHP applications which could, of course, lead to arbitrary code execution. And Denial of Service attacks. And scripted content execution within the context of an exploited site. And information leaks due to the bypassing of security.

And the workaround is? Err, it is non-existent actually. If you are a PHP 5 user then you really should make sure you are using the latest available version.
News Story Tags: gentoo, linux, php, security
Similar Threads
 
 
Comments on this News Story
May 28th, 2007
0

Re: Gentoo Linux PHP Security Advisory

They could move over to ASP
Junior Poster
cutepinkbunnies is offline Offline
143 posts
since Apr 2006
May 28th, 2007
0

Re: Gentoo Linux PHP Security Advisory

Just curious, if this is a PHP flaw, then how come it is only affecting Gentoo? Or is Gentoo simply giving the warning on behalf of all PHP 5 users?
Vampirical Lurker
John A is offline Offline
5,055 posts
since Apr 2006
May 29th, 2007
0

Re: Gentoo Linux PHP Security Advisory

>They could move over to ASP
microworld of microsoft??? you must by joking. For once it is damn slow, for two it crash often then windows and connection to db is awful. I don't know why all computing colleges actualy teach VB and related products

the Month of PHP Bugs can be found here http://www.php-security.org/
Code tags enforcer
peter_budo is offline Offline
6,652 posts
since Dec 2004
May 30th, 2007
0

Re: Gentoo Linux PHP Security Advisory

Gentoo is the source of the advisory, sorry for any confusion.
The News Guy
newsguy is offline Offline
448 posts
since Apr 2007
Message:
Previous Thread in Networking Forum Timeline: router test
Next Thread in Networking Forum Timeline: problems with web server in linux





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC