about

welcome to my space

themes
pages
  • science help thermo
  • do you like scampi
  • what are the best pl
  • any idea how to get
  • help me about reproa
  • how can i put videos
  • question about quest
  • i had a very weird d
  • why was tom cruise a
  • do you know how i ca
  • does he like me and
  • did youtube resoluti
  • how do i put my xtra
  • categories
    archive
    et cetera



    Wednesday, January 07, 2009, filed under baohewan.com
    The Computer Emergency Response Team Coordination Center (CERT/CC) Wednesday warned of multiple vulnerabilities in the PHP scripting language which would allow a remote attacker to execute arbitrary code with the privileges of the PHP process on a victim's system.

    The flaws were discovered and first reported by Stefan Esser of e-matters, a member of the PHP developer team.

    PHP is widely used in Web development and can be installed on a variety of Web servers, including Apache, IIS, Caudium, Netscape and iPlanet, OmniHTTPd and others. Esser said the vulnerabilities lie in the php_mime_split function, allowing an attacker to either execute arbitrary code with the privileges of the Web server or interrupt normal operations of the Web server.

    Esser said he found a number of bugs in various versions of PHP, including:

    Esser noted that most of the vulnerabilities are exploitable only on Linux or Solaris, but said the "heap off by one" flaw is only exploitable on x86 architecture and the "arbitrary heap overflow" in PHP3 is exploitable on most operating systems and architectures, including *BSD.

    PHP users can get around the flaws by upgrading to PHP version 4.1.2. If upgrading is not possible, patches for older versions are available here.

    Users of version 4.20-dev are not vulnerable to the bugs because the fileupload code was completely rewritten for that branch.

    If neither upgrading nor applying a patch is possible, PHP users can avoid the vulnerabilities by disabling fileupload support. To accomplish this, edit the PHP configuration file php.ini to "file_uploads = off." This setting only applies to version 4.0.3 and above, and will prevent users from using fileuploads.




    #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info about Security Flaws Found in PHP , Please add it free.

    divider