UGN Security Forums
My ProfileMember DirectoryLogin
Search our ForumsView our FAQView our Site Rules
View our CalendarView our Active TopicsGo to our Main Page

UGN Security Store
 

Network Sites UGN Security, Elite Web Gamers, Back of the Web, EveryDay Helper, VNC Web Design & Development
Our Sponsors

Latest Postings
Owning Servers
by Gizmo
08/25/08 10:21 AM
my old account still exists!
by Gizmo
08/19/08 02:27 PM
Burger King gone Wild!
by Gizmo
08/08/08 11:42 PM
PDX 2600
by rbcp
08/07/08 12:46 AM
The Pirate Bay- shut down?
by ZER0_DECEPTION
08/05/08 09:07 PM
Windows Events for Changing Access rights to a folder or a File
by Gizmo
08/05/08 12:32 PM
question about IE and CSS
by §intå×
08/04/08 08:51 PM
Server
by Gizmo
08/01/08 01:29 AM
Topic Options
#39977 - 12/17/04 04:51 AM Big security holes found in PHP
Ice Offline
UGN News Staff

Registered: 11/29/02
Posts: 1146
Loc: Canada
The PHP development team has released an update for the widely used scripting language that fixes a number of highly serious bugs, according to the project and independent security researchers.

The developers warned that users should update to PHP 4.3.10 immediately, since some of the bugs are relatively easy to exploit.

Stefan Esser of the Hardened PHP Project, which discovered the most serious flaws during development of security add-ons for PHP, said in an advisory the bugs range "from buffer overflows, to information leak vulnerabilities and path truncation vulnerabilities, to safe_mode restriction bypass vulnerabilities".

The most immediately dangerous flaws relate to PHP's variable unserialiser, unserialize (), which can allow attackers to execute malicious code on a system. "A lot of PHP applications expose the easy-to-exploit unserialize() vulnerability to remote attackers," Esser wrote. He noted that the Hardened-PHP patch makes some of the exploits ineffective.

Attackers could make use of some of the other vulnerabilities to retrieve secret data from the "apache" Web server process, bypass security restrictions and gain escalated privileges, Esser said.

Secunia, an independent security research firm based in Denmark, gave the flaws a "highly critical" rating. The PHP update also fixes more than 30 non-critical bugs, PHP developers said. A complete list of changes is available on the PHP website.

PHP is one of the most commonly used scripting languages on the Internet, and is often embedded in HTML pages.

Techworld News
_________________________
Good artists copy, great artists
steal.

-Picasso

Top
Our Sponsors
Sponsor Our Sponsors

Top  
#39978 - 12/17/04 04:22 PM Re: Big security holes found in PHP
§intå× Administrator Offline
UGN Elite
*****

Registered: 12/03/02
Posts: 3250
Loc: here
First, I love your site.

Second, I must say this makes me sad and happy. Sad PHP left gaping holes in there. Happy they have fixed them. Now to see if my host has updated. Thanx.
_________________________
My New site OpenEyes

Top



Forum Stats
6911 Members
44 Forums
10460 Topics
45198 Posts

Max Online: 677 @ 06/30/07 10:06 PM
Top Posters
Gizmo 6929
UGN Security 3436
§intå× 3250
IceMyst 1449
SilentRage 1273
Ice 1146
pergesu 1134
Infinite 1039
jonconley 954
Girlie 903
Newest Members
red queen, byopc, cybermox, NiPah, mcscrwdy25
6911 Registered Users
Who's Online
1 Registered (Gizmo), 11 Guests and 3 Spiders online.
Key: Admin, Global Mod, Mod
Latest News
Update Humpday - Aug 27, 2008
by Gizmo
Yesterday at 12:58 AM
Update Humpday - Aug 20, 2008
by Gizmo
08/21/08 01:48 AM
Update Humpday - Aug 14, 2008
by Gizmo
08/14/08 08:33 AM
Update Humpday - Aug 06, 2008
by Gizmo
08/06/08 08:05 AM
Update Humpday - Jul 30th, 2008
by Gizmo
07/31/08 11:17 AM


Donate

Get the Google FireFox Toolbar
Get Firefox!
Get FireFox!