Bug 152802

Summary: CAN-2004-0958,0959 - PHP: Memory disclosure and arbitrary location file upload
Product: [Retired] Fedora Legacy Reporter: Marc Deslauriers <marc.deslauriers>
Component: Package requestAssignee: Fedora Legacy Bugs <bugs>
Status: CLOSED DUPLICATE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: simon
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: LEGACY
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description David Lawrence 2005-03-30 23:27:59 UTC
Two bugs in PHP may allow the disclosure of portions of memory and
allow remote attackers to upload files to arbitrary locations.

Bad array parsing in the rfc1867.c file could lead to the overwriting
of the $_FILES array, which in turn could allow an attacker to write
arbitrary files with the permission of the user running apache.

Bad array parsing in php_variables.c could lead to show arbitrary memory
content such as pieces of php code and other data.
This affects all GET, POST or COOKIES variables.

Reference:
http://www.securityfocus.com/archive/1/375294
http://www.securityfocus.com/archive/1/375370
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134975
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134976
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134973
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134971



------- Additional Comments From simon 2004-10-08 09:35:03 ----

After going over the source for redhat 7.3 (php 4.1.2) I don't believe it is 
vulnerable to either of these issues. 
 
In the case of the rfc1867.c patch, the start of it is over 400 lines beyond 
the 4.1.2 file EOF. 
 
The variables.c file shows no remote relation to the patched code. 
 
- Si 



------- Additional Comments From marcdeslauriers 2004-10-09 05:07:08 ----

Confirmed, rh73 is not vulnerable.




------- Additional Comments From marcdeslauriers 2004-10-09 05:18:10 ----

rh9 doesn't look affected by this either.




------- Additional Comments From marcdeslauriers 2004-10-09 05:26:50 ----

...and FC1 doesn't seem affected.

I'm closing this bug as it seems our platforms are not affected.
If anyone thinks otherwise, please re-open.




------- Additional Comments From bugzilla.fedora.us 2004-12-15 11:09:37 ----

just to help with later searching, the first vuln is CAN-2004-0958 and the
second is CAN-2004-0959.

marc: can you add this to the summary?



------- Additional Comments From bugzilla.fedora.us 2005-01-08 12:26:30 ----

these vulns apparently DID affect FC1.  they have been fixed in bug 2344



------- Additional Comments From bugzilla.fedora.us 2005-01-09 12:45:18 ----



*** This bug has been marked as a duplicate of 2344 ***



------- Bug moved to this database by dkl 2005-03-30 18:27 -------

This bug previously known as bug 2141 at https://bugzilla.fedora.us/
https://bugzilla.fedora.us/show_bug.cgi?id=2141
Originally filed under the Fedora Legacy product and Package request component.

Unknown priority P2. Setting to default priority "normal".
Unknown platform PC. Setting to default platform "All".
Setting qa contact to the default for this product.
   This bug either had no qa contact or an invalid one.