Re: PHP 4.1.1 security bug

From: Tobias Roth (roth@iamexwi.unibe.ch)
Date: 02/28/02


Date: Thu, 28 Feb 2002 11:55:10 +0100
From: Tobias Roth <roth@iamexwi.unibe.ch>
To: freebsd-security@freebsd.org


> On Wed, Feb 27, 2002 at 01:11:23PM -0500, Mit Rowe wrote:
> > Ref:
> > http://www.php.net
> > http://security.e-matters.de/advisories/012002.html
>
> The advisory mentions a workaround (Recommendation) for php4
> (file_uploads in php.ini), but nothing for php3 - does anyone know if
> there is something that can be done for that besides disabling it?
> (until it's finished recompiling, I mean)

I tried this workaround, but I don't know if everything is ok:
with file_uploads = On, phpinfo() shows file_uploads = 1
with file_uploads = Off, phpinfo() shows file_uploads = no value

so is 'no value' OK? I'd rather see a 'Off' instead

cheers, T.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: [BUG/WARN] Error initialising drivers in PCI
    ... On 2/19/07, Bartlomiej Zolnierkiewicz wrote: ... Just disabling ata_piix should workaround the issue. ... I have done this and the message goes away in boot logs. ...
    (Linux-Kernel)
  • Re: ADODB.stream critical update?
    ... I totally agree about disabling certain technologies, it may mean a few Web ... all the recent vulnerabilities. ... >> It looks more like a temporary workaround to me until they get some real ...
    (microsoft.public.security)
  • Re: Problem with VPN and LMcompatibility level
    ... far as I know there is no workaround. ... Disabling lm authentication is much ... more important than disabling ntlm. ...
    (microsoft.public.windows.server.networking)
  • KB835732
    ... causes computer to hang at startup. ... Using the workaround ... of disabling te IPSEC service does not help. ...
    (microsoft.public.win2000.advanced_server)
  • Re: Getting mouse events in disabled buttons
    ... MS Windows blocks any user input from ... The only possible workaround I can think of is to further derive your own ... button and instead of actually disabling it, change its display so it simply ... looks disabled, but still recieves events. ...
    (microsoft.public.vc.mfc)