Re: PHP Security Hole
by "Keith Sellars" <Keith(at)webgraffix.com>
|
| Date: |
Fri, 1 Mar 2002 09:51:42 -0500 |
| To: |
<hwg-languages(at)hwg.org>, "Norman Bunn" <norman.bunn(at)craftedsolutions.com> |
| References: |
craftedsolutions |
| |
todo: View
Thread,
Original
|
|
http://security.e-matters.de/advisories/012002.html
Here is another link about the same subject. My server company (pair.com)
has just completed a complete rebuild of their Apache FreeBSD O/S as a
result of this security issue. It was severe enough, in their opinion, for
them to do so on an emergency basis.
However, according to my understanding of the documentation, Apache FreeBSD
running the version of PHP that they had already was not subject to the
vulnerability. In either case, it's better safe than sorry.
Thanks,
Keith D Sellars
WebGraffix
www.webgraffix.com
"Making database sites seem easy"
----- Original Message -----
From: "Norman Bunn" <norman.bunn(at)craftedsolutions.com>
To: <hwg-languages(at)hwg.org>
Sent: Friday, March 01, 2002 8:42 AM
Subject: PHP Security Hole
> Security hole uncovered in PHP
>
> A buffer-flow vulnerability in the open-source PHP scripting language
could
> allow an attacker to run malicious code on a victim's site.
> http://computerworld.com/nlt/1%2C3590%2CNAV47_STO68693_NLTPM%2C00.html
>
> Thought you'd like to know,
>
> Norman
>
>
HWG: hwg-languages mailing list archives,
maintained by Webmasters @ IWA
This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.