* Technical Description *
Multiple vulnerabilities were identified in PHP, which may be exploited by attackers to conduct denial of service or bypass certain security restrictions.
- The first problem resides in the "swf_openfile()", and could be exploited to bypasses safe mode restrictions. In conjunction with application vulnerabilities this could potentially allow overwriting arbitrary files.
- The second vulnerability resides in the "php_handle_iff()" and "php_handle_jpeg()" (ext/standard/image.c) functions reachable from the PHP function getimagesize(), which may be exploited by remote attackers to consume 100% CPU resources on a vulnerable system.
* Affected Products *
PHP version 4.2.2 and prior
PHP version 4.3.10 and prior
PHP version 5.0.3 and prior
* Solution *
PHP version 4.3.11 or version 5.0.4 :
http://www.php.net/downloads.php
* References *
http://www.php.net/release_4_3_11.php
http://www.php.net/ChangeLog-5.php
http://www.idefense.com/application/poi/display?id=222&type=vulnerabilities

ino
05-04-03 13:23
0개
3,022회
PHP 4.x/5.x Denial of Service and Security Bypass Vulnerabilities
댓글목록
등록된 댓글이 없습니다.