pecl-apc: arbitrary code execution
| Package(s): | pecl-apc | CVE #(s): | CVE-2008-1488 | ||||||||||||||||
| Created: | April 9, 2008 | Updated: | July 15, 2008 | ||||||||||||||||
| Description: | From the Gentoo advisory: Daniel Papasian discovered a stack-based buffer overflow in the apc_search_paths() function in the file apc.c when processing long filenames. A remote attacker could exploit this vulnerability to execute arbitrary code in PHP applications that pass user-controlled input to the include() function. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
