Secunia
|
|

|
|
|
|
|
|
|
Release Date: 2012-05-04 Last Update: 2012-05-14 Views: 3,869
Where:
From remote
Impact:
Exposure of sensitive information, System access,
Solution Status:
Vendor Patch
CVE Reference(s):
Two vulnerabilities have been reported in PHP, which can be exploited by malicious people to disclose certain sensitive information or compromise a vulnerable system.
1) An error when parsing certain QUERY_STRING parameters can be exploited to e.g. disclose the PHP source code or execute arbitrary code.
This vulnerability is reported in versions 5.3.12 and prior and versions 5.4.2 and prior.
2) An error in the "apache_request_headers()" function can be exploited to cause a buffer overflow.
NOTE: This vulnerability affects version 5.4 only.
Solution:
Update to versions 5.4.3 and 5.3.13.
Provided and/or discovered by:
1) De Eindbazen
2) Reported in PHP bug report.
Original Advisory:
PHP:
https://bugs.php.net/bug.php?id=61910
https://bugs.php.net/bug.php?id=61807
http://www.php.net/archive/2012.php#id2012-05-08-1
De Eindbazen:
http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/
US-CERT VU#520827:
http://www.kb.cert.org/vuls/id/520827
Deep Links:
Links available to Secunia VIM customers
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
Subject: PHP QUERY_STRING Parameters and Buffer Overflow Vulnerabilities
|
No posts yet |
|
You must be logged in to post a comment. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |