Computer Security
[EN] securityvulns.ru
no-pyccku



Multiple PHP security vulnerabilities
updated since 10.04.2006
Published:02.03.2007
Source:FULL-DISCLOSURE
SecurityVulns ID:5990
Type:library
Level:6/10
Description:Crossite scripting, DoS, protection bypass, buffer overflows.
Affected:PHP : PHP 4.4
 PHP : PHP 5.1
CVE:CVE-2006-1549 (PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.)
Original documentdocumentPHP-SECURITY, MOPB-03-2007:PHP Variable Destructor Deep Recursion Stack Overflow (02.03.2007)
 documentPHP-SECURITY, MOPB-02-2007:PHP Executor Deep Recursion Stack Overflow (02.03.2007)
 documentinfocus, Multiple PHP4/PHP5 vulnerabilities (24.04.2006)
 documentMaksymilian Arciemowicz, [Full-disclosure] copy() Safe Mode Bypass PHP 4.4.2 and 5.1.2 (10.04.2006)
 documentMaksymilian Arciemowicz, [Full-disclosure] tempnam() open_basedir bypass PHP 4.4.2 and 5.1.2 (10.04.2006)
 documentMaksymilian Arciemowicz, [Full-disclosure] function *() php/apache Crash PHP 4.4.2 and 5.1.2 (10.04.2006)
 documentMaksymilian Arciemowicz, [Full-disclosure] phpinfo() Cross Site Scripting PHP 5.1.2 and 4.4.2 (10.04.2006)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server