NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Advisories

Advisories


PHP Critical Vulnerabilities!

There are 8 of them!

By Alexandru Dumitru, Security News Editor

31st of August 2007, 13:33 GMT

Adjust text size:



Enlarge picture
The PHP version prior to 5.2.4 has been disclosed with vulnerabilities, that amongst other effects, may cause a malicious user to bypass security. This has been ranked as "moderately critical" by Secunia experts and already been solved by the vendors - just update to the latest
version!

In case you did not know, PHP stands for PHP (also the name of the firm that develops it) Hypertext Preprocessor. It works as a scripting language used to create dynamic websites. It uses syntax from C, Java and even Perl and it is embedded within HTML (Hypertext Mark-Up Language) pages for server side execution. It really comes in handy when you want to extract some info out of a database and have it displayed on a web page. You can imagine the utilities it has and why patching it is so important!

Here are a part of the flaws, as they appear on Secunia: two integer overflow errors exist within the "gdImageCreate()" and "gdImageCreateTrueColor()" functions in ext/gd/libgd/gd.c. These can be exploited to cause a heap-based buffer overflow via overly large integer values passed as parameters to e.g. the "imagecreatetruecolor()" PHP function. Another vulnerability would be the fact that two integer overflow errors exist within the "gdImageCopyResized()" function in ext/gd/libgd/gd.c. These can be exploited to cause a heap-based buffer overflow via overly large integer values passed as parameters to the "imagecopyresized()" or "imagecopyresampled()" PHP functions. And there are 6 more, which you can check out on Secunia's site.

In the new PHP 5.2.4 version they have fixed more than 120 bugs and even added a persistent connection status checker to pdo_pgsql. You can see the full benefits of updating, by clicking on this link.

TAGS:

PHP | vulnerability | critical
Read by 698 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.6/5) 5 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


PHP 4 to Reach Its End-of-Life This Year

An Introduction to php.ini

How to install PHP on IIS

Manually Configure PHP5 and Apache2

WordPress Vulnerable

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM