Re: PHP 4.1.1 security bug

From: Bob K (melange@yip.org)
Date: 02/27/02


Date: Wed, 27 Feb 2002 15:27:20 -0500
From: Bob K <melange@yip.org>
To: freebsd-security@FreeBSD.ORG

On Wed, Feb 27, 2002 at 01:11:23PM -0500, Mit Rowe wrote:
> Ref:
> http://www.php.net
> http://security.e-matters.de/advisories/012002.html

The advisory mentions a workaround (Recommendation) for php4
(file_uploads in php.ini), but nothing for php3 - does anyone know if
there is something that can be done for that besides disabling it?
(until it's finished recompiling, I mean)

-- 
Bob <melange@yip.org> | There's more to life than e-mail, supposedly.
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Critical phpwiki c99shell exploit
    ... Via the Phpwiki 1.3.x UpLoad feature some hackers from russia uploaded a php3 or php4 file, ... The uploaded file has a php, php3 or php4 extension and looks like a gif to the mime magic. ... To fix this phpwiki issue at first move the lib/plugin/UpLoad.php file out of this directory. ...
    (Bugtraq)
  • Re: [PHP] function_exists question
    ... The reason being that additional options have been added in php 4 and 5 to various standard function calls, but I'm still running a php3 and php4 server in addition to a php5 server. ... The $precision parameter was added in php4, so will not work in php3. ... However, function_exists would return TRUE for both 3 and 4, but round itself would fail if I tried to send a precision level to the php3 server. ...
    (php.general)
  • Re: tricky question
    ... Yes,I was refering to Marijn's workaround, ... >> I've just tried the recommendation made in the second paragraph, ... >> it but in export registry file there is no notepad. ...
    (microsoft.public.security.virus)
  • PHP settings
    ... PHP3 and PHP4 ... I am concerned about PHP vunerabilities. ... To unsubscribe, ...
    (freebsd-questions)
  • Re: chmod, apache and php
    ... If Apache ... Do you mean you have PHP4 and PHP3 on the same box? ... To UNSUBSCRIBE, email to debian-user-request@lists.debian.org ...
    (Debian-User)