Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Advisories

August 31st, 2007, 13:33 GMT · By Alexandru Dumitru

PHP Critical Vulnerabilities!

SHARE:

Adjust text size:



Enlarge picture
The PHP version prior to 5.2.4 has been disclosed with vulnerabilities, that amongst other effects, may cause a malicious user to bypass security. This has been ranked as "moderately critical" by Secunia experts and already been solved by the vendors - just update to the latest
version!

In case you did not know, PHP stands for PHP (also the name of the firm that develops it) Hypertext Preprocessor. It works as a scripting language used to create dynamic websites. It uses syntax from C, Java and even Perl and it is embedded within HTML (Hypertext Mark-Up Language) pages for server side execution. It really comes in handy when you want to extract some info out of a database and have it displayed on a web page. You can imagine the utilities it has and why patching it is so important!

Here are a part of the flaws, as they appear on Secunia: two integer overflow errors exist within the "gdImageCreate()" and "gdImageCreateTrueColor()" functions in ext/gd/libgd/gd.c. These can be exploited to cause a heap-based buffer overflow via overly large integer values passed as parameters to e.g. the "imagecreatetruecolor()" PHP function. Another vulnerability would be the fact that two integer overflow errors exist within the "gdImageCopyResized()" function in ext/gd/libgd/gd.c. These can be exploited to cause a heap-based buffer overflow via overly large integer values passed as parameters to the "imagecopyresized()" or "imagecopyresampled()" PHP functions. And there are 6 more, which you can check out on Secunia's site.

In the new PHP 5.2.4 version they have fixed more than 120 bugs and even added a persistent connection status checker to pdo_pgsql. You can see the full benefits of updating, by clicking on this link.
FILED UNDER:
PHP
vulnerability
critical

TELL US WHAT YOU THINK:

1,129 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


PHP 4 to Reach Its End-of-Life This Year

An Introduction to php.ini

How to install PHP on IIS

Manually Configure PHP5 and Apache2

WordPress Vulnerable

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM