LWN.net Logo

php: multiple vulnerabilities

Package(s):PHP5 CVE #(s):CVE-2012-2335 CVE-2012-2336
Created:June 11, 2012 Updated:July 5, 2012
Description: From the CVE entries:

php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c component and a query string beginning with a +- sequence. (CVE-2012-2335)

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823. (CVE-2012-2336)

Alerts:
SUSE SUSE-SU-2012:0721-1 2012-06-09
Ubuntu USN-1481-1 2012-06-19
Red Hat RHSA-2012:1045-01 2012-06-27
Red Hat RHSA-2012:1046-01 2012-06-27
Red Hat RHSA-2012:1047-01 2012-06-27
CentOS CESA-2012:1045 2012-06-27
CentOS CESA-2012:1047 2012-06-27
Oracle ELSA-2012-1045 2012-06-28
Oracle ELSA-2012-1047 2012-06-28
Oracle ELSA-2012-1046 2012-06-30
SUSE SUSE-SU-2012:0840-1 2012-07-05
Scientific Linux SL-php-20120705 2012-07-05
Scientific Linux SL-php5-20120705 2012-07-05
Scientific Linux SL-php-20120709 2012-07-09
CentOS CESA-2012:1046 2012-07-10
Gentoo 201209-03 2012-09-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds