security

Total 112
Today 0
profile_image
ino
05-04-03 13:23 0개 3,023회
PHP 4.x/5.x Denial of Service and Security Bypass Vulnerabilities
* Technical Description *



Multiple vulnerabilities were identified in PHP, which may be exploited by attackers to conduct denial of service or bypass certain security restrictions.



- The first problem resides in the "swf_openfile()", and could be exploited to bypasses safe mode restrictions. In conjunction with application vulnerabilities this could potentially allow overwriting arbitrary files.



- The second vulnerability resides in the "php_handle_iff()" and "php_handle_jpeg()" (ext/standard/image.c) functions reachable from the PHP function getimagesize(), which may be exploited by remote attackers to consume 100% CPU resources on a vulnerable system.



* Affected Products *



PHP version 4.2.2 and prior

PHP version 4.3.10 and prior

PHP version 5.0.3 and prior



* Solution *



PHP version 4.3.11 or version 5.0.4 :

http://www.php.net/downloads.php



* References *



http://www.php.net/release_4_3_11.php

http://www.php.net/ChangeLog-5.php

http://www.idefense.com/application/poi/display?id=222&type=vulnerabilities

댓글목록

등록된 댓글이 없습니다.