LWN.net Logo

pecl-apc: arbitrary code execution

Package(s):pecl-apc CVE #(s):CVE-2008-1488
Created:April 9, 2008 Updated:April 10, 2008
Description:

From the Gentoo advisory:

Daniel Papasian discovered a stack-based buffer overflow in the apc_search_paths() function in the file apc.c when processing long filenames.

A remote attacker could exploit this vulnerability to execute arbitrary code in PHP applications that pass user-controlled input to the include() function.

Alerts:
Gentoo 200804-07 2008-04-09
Mandriva MDVSA-2008:082 2008-04-09

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.