|
PHP COM Objects Security Bypass
|
|
|
|
|
Secunia Advisory:
|
SA27280
|
|
|
Release Date:
|
2007-10-23
|
|
Last Update:
|
2007-10-26
|
|
|
Critical:
|

Not critical
|
|
Impact:
|
Security Bypass
|
|
Where:
|
Local system
|
|
Solution Status:
|
Unpatched
|
|
| Software: | PHP 5.0.x PHP 5.1.x PHP 5.2.x
|
| | CVE reference: | CVE-2007-5653 (Secunia mirror)
|
|
|
This advisory is currently marked as unpatched! - Companies can be alerted when a patch is released! |
|
|
Description: shinnai has discovered a vulnerability in PHP, which can be exploited by malicious, local users to bypass certain access restrictions.
The vulnerability is caused due to PHP incorrectly enforcing access restrictions when handling COM objects. This can be exploited to bypass certain security restrictions (e.g. the "safe_mode" directive) by directly invoking COM methods.
The vulnerability is confirmed in PHP 5.2.4 for Windows. Other Windows versions may also be affected.
Solution: Grant only trusted users permissions to execute PHP code.
Provided and/or discovered by: shinnai
Changelog: 2007-10-26: Added CVE reference.
Original Advisory: http://milw0rm.com/exploits/4553
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
39 Related Secunia Security Advisories, displaying 10
|
|
|
1. PHP Multiple Vulnerabilities
|
|
2. PHP Multiple Vulnerabilities
|
|
3. PHP Multiple Vulnerabilities
|
|
4. PHP "glob()" Code Execution Vulnerability
|
|
5. PHP Multiple Extensions Buffer Overflow Vulnerabilities
|
|
6. PHP Integer Overflow Vulnerability and Security Bypass
|
|
7. PHP crypt() Race Condition Vulnerability
|
|
8. PHP "gdPngReadData()" Truncated PNG Data Denial of Service
|
|
9. PHP SOAP Extension HTTP Authentication Weak Nonce
|
|
10. PHP Multiple Vulnerabilities
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|