CVE-2008-0599
CVE-2008-0599
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://cvs.php.net/viewvc.cgi/php-src/sapi/cgi/cgi_main.c?r1=1.267.2.15.2.50.2.12&r2=1.267.2.15.2.50.2.13&diff_format=uhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01476437http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.htmlhttp://marc.info/?l=bugtraq&m=124654546101607&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://secunia.com/advisories/30048http://secunia.com/advisories/30083http://secunia.com/advisories/30345http://secunia.com/advisories/30616http://secunia.com/advisories/30757http://secunia.com/advisories/30828http://secunia.com/advisories/31200