Bug 152802 - CAN-2004-0958,0959 - PHP: Memory disclosure and arbitrary location file upload
CAN-2004-0958,0959 - PHP: Memory disclosure and arbitrary location file upload
Status: CLOSED DUPLICATE
Product: Fedora Legacy
Classification: Retired
Component: Package request (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Fedora Legacy Bugs
LEGACY
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2004-10-08 06:45 EDT by Marc Deslauriers
Modified: 2008-05-01 11:38 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description David Lawrence 2005-03-30 18:27:59 EST
Two bugs in PHP may allow the disclosure of portions of memory and
allow remote attackers to upload files to arbitrary locations.

Bad array parsing in the rfc1867.c file could lead to the overwriting
of the $_FILES array, which in turn could allow an attacker to write
arbitrary files with the permission of the user running apache.

Bad array parsing in php_variables.c could lead to show arbitrary memory
content such as pieces of php code and other data.
This affects all GET, POST or COOKIES variables.

Reference:
http://www.securityfocus.com/archive/1/375294
http://www.securityfocus.com/archive/1/375370
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134975
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134976
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134973
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134971



------- Additional Comments From simon@nzservers.com 2004-10-08 09:35:03 ----

After going over the source for redhat 7.3 (php 4.1.2) I don't believe it is 
vulnerable to either of these issues. 
 
In the case of the rfc1867.c patch, the start of it is over 400 lines beyond 
the 4.1.2 file EOF. 
 
The variables.c file shows no remote relation to the patched code. 
 
- Si 



------- Additional Comments From marcdeslauriers@videotron.ca 2004-10-09 05:07:08 ----

Confirmed, rh73 is not vulnerable.




------- Additional Comments From marcdeslauriers@videotron.ca 2004-10-09 05:18:10 ----

rh9 doesn't look affected by this either.




------- Additional Comments From marcdeslauriers@videotron.ca 2004-10-09 05:26:50 ----

...and FC1 doesn't seem affected.

I'm closing this bug as it seems our platforms are not affected.
If anyone thinks otherwise, please re-open.




------- Additional Comments From bugzilla.fedora.us@beej.org 2004-12-15 11:09:37 ----

just to help with later searching, the first vuln is CAN-2004-0958 and the
second is CAN-2004-0959.

marc: can you add this to the summary?



------- Additional Comments From bugzilla.fedora.us@beej.org 2005-01-08 12:26:30 ----

these vulns apparently DID affect FC1.  they have been fixed in bug 2344



------- Additional Comments From bugzilla.fedora.us@beej.org 2005-01-09 12:45:18 ----



*** This bug has been marked as a duplicate of 2344 ***



------- Bug moved to this database by dkl@redhat.com 2005-03-30 18:27 -------

This bug previously known as bug 2141 at https://bugzilla.fedora.us/
https://bugzilla.fedora.us/show_bug.cgi?id=2141
Originally filed under the Fedora Legacy product and Package request component.

Unknown priority P2. Setting to default priority "normal".
Unknown platform PC. Setting to default platform "All".
Setting qa contact to the default for this product.
   This bug either had no qa contact or an invalid one.


Note You need to log in before you can comment on or make changes to this bug.