May 22, 2012, 09:52:03 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: THC is up and running !
 

 
advertisement:

Pages: [1]
  Print  
Author Topic: RSS: PHP 5.3.9 'php_register_variable_ex()' Code Execution  (Read 51 times)
zomgwtfbbq
Challenge Coder
Administrator
Hero Member
*****

Karma: +31340/-1
Posts: I am a geek!!


thc title: thc elite
thc points: 3315
challenges: (69/83)

View Profile
« on: February 04, 2012, 01:29:00 AM »
Share on FacebookFacebook Share

PHP 5.3.9 'php_register_variable_ex()' Code Execution


Synopsis :

The remote web server uses a version of PHP that is affected by a
code execution vulnerability.

Description :

According to its banner, the version of PHP installed on the remote
host is 5.3.9. This version reportedly is affected by a code
execution vulnerability.

Specifically, the fix for the hash collision denial of service
vulnerability (CVE-2011-4885) itself has introduced a remote code
execution vulnerability in the function 'php_register_variable_ex()' in
the file 'php_variables.c'. A new configuration variable,
'max_input_vars', was added as a part of the fix. If the number of
input variables exceeds this value and the variable being processed is
an array, code execution can occur.

See also :


only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
https://gist.github.com/1725489


only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
http://www.php.net/ChangeLog-5.php#5.3.10


only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
http://www.nessus.org/u?d1ee2de8


only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
http://svn.php.net/viewvc?view=revision&revision=323007


Solution :

Upgrade to PHP version 5.3.10 or later.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)



original thread:
only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
http://www.nessus.org/plugins/index.php?view=single&id=57825
Logged


only registered users with at least 25 hack challenge points can see links:
  click here in order to visit the hack challenges


Ook al ben ik een slet toch houdt ik van je..
Pages: [1]
  Print  
 
Jump to:  


SMF Board hacked and modded by zomgwtfbekjam aka Rembo from Tools & Design