[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

UNIRAS Brief - 986/05 - PHP 5.1.1 released fixing multiple vulnerabilities



-----BEGIN PGP SIGNED MESSAGE-----

- ----------------------------------------------------------------------------------
   UNIRAS (UK Govt CERT) Briefing Notice - 986/05 dated 29.11.05  Time: 10:20  
  UNIRAS is part of NISCC (National Infrastructure Security Co-ordination Centre)
- ---------------------------------------------------------------------------------- 
  UNIRAS material is also available from its website at www.uniras.gov.uk and
         Information about NISCC is available from www.niscc.gov.uk
- ----------------------------------------------------------------------------------

Title
=====

PHP 5.1.1 released fixing multiple vulnerabilities

Detail
====== 

 PHP 5.1.0 and prior contain multiple vulnerabilities which may allow 
 arbitrary code execution or denial of service attacks. The PHP 
 Development Team have released an advisory [1] regarding these 
 vulnerabilities. For full details of all changes in PHP 5.1.1, please 
 refer to the PHP change log [2]. 


- -----BEGIN PGP SIGNED MESSAGE----- 
Hash: SHA1 

=========================================================================== 

            PHP 5.1.1 released fixing multiple vulnerabilities 
                             28 November 2005 
- - --------------------------------------------------------------------------- 

         

Product:           PHP 5.1.0 and prior 
Operating System:  Linux variants 
                   UNIX variants 
                   Windows 
                   Mac OS X 
Impact:            Execute Arbitrary Code/Commands 
                   Denial of Service 
                   Cross-site Scripting 
                   Inappropriate Access 
Access:            Remote/Unauthenticated 

Ref:               CAN-2005-2491 

Original Bulletin: http://news.php.net/php.announce/58 

OVERVIEW: 
        
        PHP 5.1.0 and prior contain multiple vulnerabilities which may allow 
        arbitrary code execution or denial of service attacks. The PHP 
        Development Team have released an advisory [1] regarding these 
        vulnerabilities. For full details of all changes in PHP 5.1.1, please 
        refer to the PHP change log [2]. 


IMPACT: 

        1. Execute Arbitrary Code       

        Integer overflows in pcre_compile.c allows attackers to overflow heap 
        buffers via quantifier values in regular expressions, potentially 
        leading to the execution of arbitrary code. 


        2. Denial of Service 
        
        Multiple vulnerabilities exist which allow memory corruption 
        potentially leading to a denial of service condition. For more 
        information, see the PHP change log [2]. 

        
        3. Cross-site scripting 
        
        A Cross-site scripting vulnerability exists in the phpinfo() function 
        which may lead to information disclosure. 

        
        4. Inappropriate Access 
        
        Multiple vulnerable functions exist which allow modification of 
        configuration directives or variables.  For full details, please refer 
        to the PHP change log [2]. 
        
        
MITIGATION: 

        It is recommended that users of earlier versions of PHP, including 
        those running beta versions of PHP 5.1.0, upgrade to version 5.1.1. 
        

REFERENCES: 

[1] http://news.php.net/php.announce/58 
[2] http://www.php.net/ChangeLog-5.php#5.1.1 


=========================================================================== 
iQCVAwUBQ4uY0ih9+71yA2DNAQLMOAP9G0nV5S3MHW/kpDey+6MdeNgj+IegGBWS 
Gjp0lp1RVRVx2NoIIJSVENEd1I67rYpSMzftW3K26JMAKrwcAebJhMI51Dj4JV/b 
ZUpGfqpytawrEOxf2TDb8UoTx+H2t3bHsHFxW6nSSqRPw9cROUou91KvzoEWqY5X 
0001eeCLdDU= 
=tHd0 
- -----END PGP SIGNATURE----- 


- ----------------------------------------------------------------------------------

For additional information or assistance, please contact the HELP Desk by 
telephone or Not Protectively Marked information may be sent via 
EMail to: uniras@xxxxxxxxxxxx

Office Hours:
Mon - Fri: 08:30 - 17:00 Hrs
Tel: +44 (0) 870 487 0748 Ext 4511
Fax: +44 (0) 870 487 0749

Outside of Office Hours:
On Call Duty Officer:
Tel: +44 (0) 870 487 0748 and follow the prompts

- ----------------------------------------------------------------------------------
UNIRAS wishes to acknowledge the contributions of PHP for the information 
contained in this Briefing. 
- ----------------------------------------------------------------------------------
This Briefing contains the information released by the original author. Some 
of the information may have changed since it was released. If the vulnerability 
affects you, it may be prudent to retrieve the advisory from the canonical site 
to ensure that you receive the most current information concerning that problem.

Reference to any specific commercial product, process, or service by trade 
name, trademark manufacturer, or otherwise, does not constitute or imply 
its endorsement, recommendation, or favouring by UNIRAS or NISCC.  The views 
and opinions of authors expressed within this notice shall not be used for 
advertising or product endorsement purposes.

Neither UNIRAS or NISCC shall also accept responsibility for any errors 
or omissions contained within this briefing notice. In particular, they shall 
not be liable for any loss or damage whatsoever, arising from or in connection 
with the usage of information contained within this notice.

UNIRAS is a member of the Forum of Incident Response and Security Teams (FIRST) 
and has contacts with other international Incident Response Teams (IRTs) in 
order to foster cooperation and coordination in incident prevention, to prompt 
rapid reaction to incidents, and to promote information sharing amongst its 
members and the community at large. 
- ----------------------------------------------------------------------------------
<End of UNIRAS Briefing>

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQCVAwUBQ4wruYpao72zK539AQHIJgP/YFXS2dYTqs6F9j/rCr83a+5QBuPytx/o
OSNBROBum5FS7WknflZC7R2y2+MyEkCDDSNwDScQGRpVG2Op+J6fHQAshV3lmOKC
+tAcoTKbkTXxcotw2PTqCp7E2SY8p+px53adFwpZihWD6qnbiI/thFFojYlBN5J9
0ncUadq/QC8=
=r5Iq
-----END PGP SIGNATURE-----


______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________

______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________