Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.52074
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2005:072 (php)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to php
announced via advisory MDKSA-2005:072.

A number of vulnerabilities are addressed in this PHP update:

Stefano Di Paolo discovered integer overflows in PHP's pack(),
unpack(), and shmop_write() functions which could allow a malicious
script to break out of safe mode and execute arbitray code with
privileges of the PHP interpreter (CVE-2004-1018
this was previously
fixed in Mandrakelinux >= 10.0 in MDKSA-2004:151).

Stefan Esser discovered two safe mode bypasses which would allow
malicious scripts to circumvent path restrictions by using
virtual_popen() with a current directory containing shell meta-
characters (CVE-2004-1063) or by creating a specially crafted
directory whose length exceeded the capacity of realpath()
(CVE-2004-1064
both of these were previously fixed in Mandrakelinux
>= 10.0 in MDKSA-2004:151).

Two Denial of Service vulnerabilities were found in the getimagesize()
function which uses the format-specific internal functions
php_handle_iff() and php_handle_jpeg() which would get stuck in
infinite loops when certain (invalid) size parameters are read from
the image (CVE-2005-0524 and CVE-2005-0525).

An integer overflow was discovered in the exif_process_IFD_TAG()
function in PHP's EXIF module. EXIF tags with a specially crafted
Image File Directory (IFD) tag would cause a buffer overflow which
could be exploited to execute arbitrary code with the privileges of
the PHP server (CVE-2005-1042).

Another vulnerability in the EXIF module was also discovered where
headers with a large IFD nesting level would cause an unbound
recursion which would eventually overflow the stack and cause the
executed program to crash (CVE-2004-1043).

All of these issues are addressed in the Corporate Server 2.1 packages
and the last three issues for all other platforms, which had
previously included the first two issues but had not been mentioned
in MDKSA-2004:151.

Affected versions: 10.0, 10.1, 10.2, Corporate 3.0,
Corporate Server 2.1


Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2005:072

Risk factor : Critical

CVSS Score:
10.0

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-1018
BugTraq ID: 12045
http://www.securityfocus.com/bid/12045
Bugtraq: 20041215 Advisory 01/2004: Multiple vulnerabilities in PHP 4/5 (Google Search)
http://marc.info/?l=bugtraq&m=110314318531298&w=2
Bugtraq: 20041219 PHP shmop.c module permits write of arbitrary memory. (Google Search)
http://www.securityfocus.com/archive/1/384920
https://bugzilla.fedora.us/show_bug.cgi?id=2344
HPdes Security Advisory: HPSBMA01212
http://www.securityfocus.com/advisories/9028
http://www.mandriva.com/security/advisories?name=MDKSA-2004:151
http://www.mandriva.com/security/advisories?name=MDKSA-2005:072
http://www.hardened-php.net/advisories/012004.txt
http://www.osvdb.org/12411
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10949
http://www.redhat.com/support/errata/RHSA-2005-032.html
http://www.redhat.com/support/errata/RHSA-2005-816.html
https://www.ubuntu.com/usn/usn-99-1/
XForce ISS Database: php-shmopwrite-outofbounds-memory(18515)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18515
Common Vulnerability Exposure (CVE) ID: CVE-2004-1063
BugTraq ID: 11964
http://www.securityfocus.com/bid/11964
http://www.securityfocus.com/archive/1/384545
Conectiva Linux advisory: CLA-2005:915
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000915
http://www.gentoo.org/security/en/glsa/glsa-200412-14.xml
http://www.osvdb.org/12412
XForce ISS Database: php-safemodeexecdir-restriction-bypass(18511)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18511
Common Vulnerability Exposure (CVE) ID: CVE-2004-1064
https://www.ubuntu.com/usn/usn-99-2/
XForce ISS Database: php-realpath-safemode-bypass(18512)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18512
Common Vulnerability Exposure (CVE) ID: CVE-2005-0524
http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html
http://www.gentoo.org/security/en/glsa/glsa-200504-15.xml
http://www.securityfocus.com/archive/1/394797
http://www.osvdb.org/15183
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9310
http://www.redhat.com/support/errata/RHSA-2005-405.html
http://www.redhat.com/support/errata/RHSA-2005-406.html
http://securitytracker.com/id?1013619
http://secunia.com/advisories/14792
SuSE Security Announcement: SUSE-SA:2005:023 (Google Search)
http://www.vupen.com/english/advisories/2005/0305
XForce ISS Database: php-phphandleiff-dos(19920)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19920
Common Vulnerability Exposure (CVE) ID: CVE-2005-0525
Debian Security Information: DSA-708 (Google Search)
http://www.debian.org/security/2005/dsa-708
Debian Security Information: DSA-729 (Google Search)
http://www.debian.org/security/2005/dsa-729
http://www.osvdb.org/15184
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11703
Common Vulnerability Exposure (CVE) ID: CVE-2005-1042
APPLE-SA-2005-06-08
GLSA-200504-15
MDKSA-2005:072
RHSA-2005:405
RHSA-2005:406
USN-112-1
https://usn.ubuntu.com/112-1/
http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.33&r2=1.118.2.34&ty=u
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154021
oval:org.mitre.oval:def:10822
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10822
Common Vulnerability Exposure (CVE) ID: CVE-2004-1043
Bugtraq: 20041225 Microsoft Internet Explorer SP2 Fully Automated Remote Compromise (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2004-12/0426.html
Cert/CC Advisory: TA05-012B
http://www.us-cert.gov/cas/techalerts/TA05-012B.html
CERT/CC vulnerability note: VU#972415
http://www.kb.cert.org/vuls/id/972415
Microsoft Security Bulletin: MS05-001
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-001
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1349
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1963
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2830
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3496
XForce ISS Database: ie-helpactivexcontrol-save-file(18311)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18311
Common Vulnerability Exposure (CVE) ID: CVE-2005-1043
http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.29&r2=1.118.2.30&ty=u
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154025
oval:org.mitre.oval:def:10307
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10307
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.