Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Published: 2005-01-10
Updated: 2020-12-08
Summary
Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
Vulnerable Configurations
Exploit-Db
description | PHP 3/4/5 Multiple Local And Remote Vulnerabilities (2). CVE-2004-1018. Dos exploit for php platform |
id | EDB-ID:24855 |
last seen | 2016-02-03 |
modified | 2004-12-15 |
published | 2004-12-15 |
reporter | Slythers |
source | https://www.exploit-db.com/download/24855/ |
title | PHP 3/4/5 - Multiple Local And Remote Vulnerabilities 2 |
description | PHP 3/4/5 Multiple Local And Remote Vulnerabilities (1). CVE-2004-1018. Dos exploit for php platform |
id | EDB-ID:24854 |
last seen | 2016-02-03 |
modified | 2004-12-15 |
published | 2004-12-15 |
reporter | Stefan Esser |
source | https://www.exploit-db.com/download/24854/ |
title | PHP 3/4/5 - Multiple Local And Remote Vulnerabilities 1 |
Nessus
NASL family | Red Hat Local Security Checks |
NASL id | REDHAT-RHSA-2005-032.NASL |
description | Updated php packages that fix various security issues are now available for Red Hat Enterprise Linux 4. This update has been rated as having important security impact by the Red Hat Security Response Team. PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Web server. Flaws including possible information disclosure, double free, and negative reference index array underflow were found in the deserialization code of PHP. PHP applications may use the unserialize function on untrusted user data, which could allow a remote attacker to gain access to memory or potentially execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-1019 to this issue. A flaw in the exif extension of PHP was found which lead to a stack overflow. An attacker could create a carefully crafted image file in such a way which, if parsed by a PHP script using the exif extension, could cause a crash or potentially execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-1065 to this issue. Flaws were found in shmop_write, pack, and unpack PHP functions. These functions are not normally passed user-supplied data, so would require a malicious PHP script to be exploited. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-1018 to this issue. Users of PHP should upgrade to these updated packages, which contain fixes for these issues. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 17166 |
published | 2005-02-22 |
reporter | This script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/17166 |
title | RHEL 4 : php (RHSA-2005:032) |
NASL family | Red Hat Local Security Checks |
NASL id | REDHAT-RHSA-2005-031.NASL |
description | Updated php packages that fix various security issues are now available for Red Hat Enterprise Linux 2.1. PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Web server. A double-free bug was found in the deserialization code of PHP. PHP applications use the unserialize function on untrusted user data, which could allow a remote attacker to gain access to memory or potentially execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-1019 to this issue. Flaws were found in the pack and unpack PHP functions. These functions do not normally pass user-supplied data, so they would require a malicious PHP script to be exploited. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-1018 to this issue. A bug was discovered in the initialization of the OpenSSL library, such that the curl extension could not be used to perform HTTP requests over SSL unless the php-imap package was installed. Users of PHP should upgrade to these updated packages, which contain fixes for these issues. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 16222 |
published | 2005-01-19 |
reporter | This script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/16222 |
title | RHEL 2.1 : php (RHSA-2005:031) |
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2005-072.NASL |
description | A number of vulnerabilities are addressed in this PHP update : Stefano Di Paolo discovered integer overflows in PHP |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18091 |
published | 2005-04-19 |
reporter | This script is Copyright (C) 2005-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18091 |
title | Mandrake Linux Security Advisory : php (MDKSA-2005:072) |
NASL family | MacOS X Local Security Checks |
NASL id | MACOSX_SECUPD2005-001.NASL |
description | he remote host is missing Security Update 2005-001. This security update contains a number of fixes for the following programs : - at commands - ColorSync - libxml2 - Mail - PHP - Safari - SquirrelMail These programs have multiple vulnerabilities which may allow a remote attacker to execute arbitrary code. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 16251 |
published | 2005-01-26 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/16251 |
title | Mac OS X Multiple Vulnerabilities (Security Update 2005-001) |
NASL family | Ubuntu Local Security Checks |
NASL id | UBUNTU_USN-99-1.NASL |
description | Stefano Di Paola discovered integer overflows in PHP |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20725 |
published | 2006-01-15 |
reporter | Ubuntu Security Notice (C) 2005-2019 Canonical, Inc. / NASL script (C) 2006-2016 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20725 |
title | Ubuntu 4.10 : php4 vulnerabilities (USN-99-1) |
NASL family | CGI abuses |
NASL id | PHP45_MULTIPLE_FLAWS.NASL |
description | According to its banner, the version of PHP installed on the remote host is prior to 4.3.10 / 5.0.3. It is, therefore, affected by multiple security issues that could, under certain circumstances, allow an attacker to execute arbitrary code on the remote host, provided that the attacker can pass arbitrary data to some functions, or to bypass safe_mode. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15973 |
published | 2004-12-15 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15973 |
title | PHP < 4.3.10 / 5.0.3 Multiple Vulnerabilities |
NASL family | Red Hat Local Security Checks |
NASL id | REDHAT-RHSA-2004-687.NASL |
description | Updated php packages that fix various security issues and bugs are now available for Red Hat Enterprise Linux 3. PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Web server. Flaws including possible information disclosure, double free, and negative reference index array underflow were found in the deserialization code of PHP. PHP applications may use the unserialize function on untrusted user data, which could allow a remote attacker to gain access to memory or potentially execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-1019 to this issue. A flaw in the exif extension of PHP was found which lead to a stack overflow. An attacker could create a carefully crafted image file in such a way that if parsed by a PHP script using the exif extension it could cause a crash or potentially execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-1065 to this issue. An information disclosure bug was discovered in the parsing of |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 16041 |
published | 2004-12-23 |
reporter | This script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/16041 |
title | RHEL 3 : php (RHSA-2004:687) |
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2004-151.NASL |
description | A number of vulnerabilities in PHP versions prior to 4.3.10 were discovered by Stefan Esser. Some of these vulnerabilities were not deemed to be severe enough to warrant CVE names, however the packages provided, with the exception of the Corporate Server 2.1 packages, include fixes for all of the vulnerabilities, thanks to the efforts of the OpenPKG team who extracted and backported the fixes. The vulnerabilities fixed in all provided packages include a fix for a possible information disclosure, double free, and negative reference index array underflow in deserialization code (CVE-2004-1019). As well, the exif_read_data() function suffers from an overflow on a long sectionname; this vulnerability was discovered by Ilia Alshanetsky (CVE-2004-1065). The other fixes that appear in Mandrakelinux 9.2 and newer packages include a fix for out of bounds memory write access in shmop_write() and integer overflow/underflows in the pack() and unpack() functions. The addslashes() function did not properly escape |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15998 |
published | 2004-12-19 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15998 |
title | Mandrake Linux Security Advisory : php (MDKSA-2004:151) |
Oval
accepted | 2013-04-29T04:10:12.307-04:00 |
class | vulnerability |
contributors | name | Aharon Chernin | organization | SCAP.com, LLC |
name | Dragos Prisaca | organization | G2, Inc. |
|
definition_extensions | comment | The operating system installed on the system is Red Hat Enterprise Linux 3 | oval | oval:org.mitre.oval:def:11782 |
comment | CentOS Linux 3.x | oval | oval:org.mitre.oval:def:16651 |
comment | The operating system installed on the system is Red Hat Enterprise Linux 4 | oval | oval:org.mitre.oval:def:11831 |
comment | CentOS Linux 4.x | oval | oval:org.mitre.oval:def:16636 |
comment | Oracle Linux 4.x | oval | oval:org.mitre.oval:def:15990 |
|
description | Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion. |
family | unix |
id | oval:org.mitre.oval:def:10949 |
status | accepted |
submitted | 2010-07-09T03:56:16-04:00 |
title | Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion. |
version | 27 |
Redhat
advisories | |
rpms | - php-0:4.3.2-19.ent
- php-debuginfo-0:4.3.2-19.ent
- php-devel-0:4.3.2-19.ent
- php-imap-0:4.3.2-19.ent
- php-ldap-0:4.3.2-19.ent
- php-mysql-0:4.3.2-19.ent
- php-odbc-0:4.3.2-19.ent
- php-pgsql-0:4.3.2-19.ent
- php-0:4.3.9-3.2
- php-debuginfo-0:4.3.9-3.2
- php-devel-0:4.3.9-3.2
- php-domxml-0:4.3.9-3.2
- php-gd-0:4.3.9-3.2
- php-imap-0:4.3.9-3.2
- php-ldap-0:4.3.9-3.2
- php-mbstring-0:4.3.9-3.2
- php-mysql-0:4.3.9-3.2
- php-ncurses-0:4.3.9-3.2
- php-odbc-0:4.3.9-3.2
- php-pear-0:4.3.9-3.2
- php-pgsql-0:4.3.9-3.2
- php-snmp-0:4.3.9-3.2
- php-xmlrpc-0:4.3.9-3.2
|