Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-7068
StatusCandidate
DescriptionThe dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte.  NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.
PhaseAssigned (24.08.2009)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7068
ReferencesBUGTRAQ : 20081127 SecurityReason : PHP 5.2.6 dba_replace() destroying file
 BUGTRAQ : 20081206 Re: SecurityReason : PHP 5.2.6 dba_replace() destroying file
 BUGTRAQ : 20081206 Re: SecurityReason : PHP 5.2.6 dba_replace() destroying file
 CONFIRM : http://cvs.php.net/viewvc.cgi/php-src/NEWS?r1=1.20...
 OSVDB : 52206
 SREASONRES : 20081127 PHP 5.2.6 dba_replace() destroying file
 XF : php-dbareplace-file-corruption(47316)
SecurityVulns:PHP dba_replace() DoS

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru