Vulnerabilities > CVE-2014-8626 - Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in PHP

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
php
CWE-119
nessus

Summary

Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding.

Vulnerable Configurations

Part Description Count
Application
Php
347

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Buffer Overflow via Environment Variables
    This attack pattern involves causing a buffer overflow through manipulation of environment variables. Once the attacker finds that they can modify an environment variable, they may try to overflow associated buffers. This attack leverages implicit trust often placed in environment variables.
  • Overflow Buffers
    Buffer Overflow attacks target improper or missing bounds checking on buffer operations, typically triggered by input injected by an attacker. As a consequence, an attacker is able to write past the boundaries of allocated buffer regions in memory, causing a program crash or potentially redirection of execution as per the attackers' choice.
  • Client-side Injection-induced Buffer Overflow
    This type of attack exploits a buffer overflow vulnerability in targeted client software through injection of malicious content from a custom-built hostile service.
  • Filter Failure through Buffer Overflow
    In this attack, the idea is to cause an active filter to fail by causing an oversized transaction. An attacker may try to feed overly long input strings to the program in an attempt to overwhelm the filter (by causing a buffer overflow) and hoping that the filter does not fail securely (i.e. the user input is let into the system unfiltered).
  • MIME Conversion
    An attacker exploits a weakness in the MIME conversion routine to cause a buffer overflow and gain control over the mail server machine. The MIME system is designed to allow various different information formats to be interpreted and sent via e-mail. Attack points exist when data are converted to MIME compatible format and back.

Nessus

  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2014-1824.NASL
    descriptionUpdated php packages that fix three security issues are now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A buffer overflow flaw was found in the Exif extension. A specially crafted JPEG or TIFF file could cause a PHP application using the exif_thumbnail() function to crash or, possibly, execute arbitrary code with the privileges of the user running that PHP application. (CVE-2014-3670) A stack-based buffer overflow flaw was found in the way the xmlrpc extension parsed dates in the ISO 8601 format. A specially crafted XML-RPC request or response could possibly cause a PHP application to crash. (CVE-2014-8626) An integer overflow flaw was found in the way custom objects were unserialized. Specially crafted input processed by the unserialize() function could cause a PHP application to crash. (CVE-2014-3669) All php users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, the httpd daemon must be restarted for the update to take effect.
    last seen2020-06-01
    modified2020-06-02
    plugin id78909
    published2014-11-07
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/78909
    titleRHEL 5 : php (RHSA-2014:1824)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    # The descriptive text and package checks in this plugin were  
    # extracted from Red Hat Security Advisory RHSA-2014:1824. The text 
    # itself is copyright (C) Red Hat, Inc.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(78909);
      script_version("1.17");
      script_cvs_date("Date: 2019/10/24 15:35:39");
    
      script_cve_id("CVE-2014-3669", "CVE-2014-3670", "CVE-2014-8626");
      script_bugtraq_id(70611, 70665, 70928);
      script_xref(name:"RHSA", value:"2014:1824");
    
      script_name(english:"RHEL 5 : php (RHSA-2014:1824)");
      script_summary(english:"Checks the rpm output for the updated packages");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"The remote Red Hat host is missing one or more security updates."
      );
      script_set_attribute(
        attribute:"description", 
        value:
    "Updated php packages that fix three security issues are now available
    for Red Hat Enterprise Linux 5.
    
    Red Hat Product Security has rated this update as having Important
    security impact. Common Vulnerability Scoring System (CVSS) base
    scores, which give detailed severity ratings, are available for each
    vulnerability from the CVE links in the References section.
    
    PHP is an HTML-embedded scripting language commonly used with the
    Apache HTTP Server.
    
    A buffer overflow flaw was found in the Exif extension. A specially
    crafted JPEG or TIFF file could cause a PHP application using the
    exif_thumbnail() function to crash or, possibly, execute arbitrary
    code with the privileges of the user running that PHP application.
    (CVE-2014-3670)
    
    A stack-based buffer overflow flaw was found in the way the xmlrpc
    extension parsed dates in the ISO 8601 format. A specially crafted
    XML-RPC request or response could possibly cause a PHP application to
    crash. (CVE-2014-8626)
    
    An integer overflow flaw was found in the way custom objects were
    unserialized. Specially crafted input processed by the unserialize()
    function could cause a PHP application to crash. (CVE-2014-3669)
    
    All php users are advised to upgrade to these updated packages, which
    contain backported patches to correct these issues. After installing
    the updated packages, the httpd daemon must be restarted for the
    update to take effect."
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://access.redhat.com/security/cve/cve-2014-3669"
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://access.redhat.com/security/cve/cve-2014-3670"
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://access.redhat.com/security/cve/cve-2014-8626"
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://access.redhat.com/errata/RHSA-2014:1824"
      );
      script_set_attribute(attribute:"solution", value:"Update the affected packages.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P");
      script_set_cvss_temporal_vector("CVSS2#E:U/RL:OF/RC:C");
      script_set_attribute(attribute:"exploitability_ease", value:"No known exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"false");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-bcmath");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-cli");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-common");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-dba");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-debuginfo");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-devel");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-gd");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-imap");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-ldap");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-mbstring");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-mysql");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-ncurses");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-odbc");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-pdo");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-pgsql");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-snmp");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-soap");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-xml");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:php-xmlrpc");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:redhat:enterprise_linux:5");
    
      script_set_attribute(attribute:"patch_publication_date", value:"2014/11/06");
      script_set_attribute(attribute:"plugin_publication_date", value:"2014/11/07");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
      script_family(english:"Red Hat Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/RedHat/release", "Host/RedHat/rpm-list", "Host/cpu");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("misc_func.inc");
    include("rpm.inc");
    
    if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    release = get_kb_item("Host/RedHat/release");
    if (isnull(release) || "Red Hat" >!< release) audit(AUDIT_OS_NOT, "Red Hat");
    os_ver = eregmatch(pattern: "Red Hat Enterprise Linux.*release ([0-9]+(\.[0-9]+)?)", string:release);
    if (isnull(os_ver)) audit(AUDIT_UNKNOWN_APP_VER, "Red Hat");
    os_ver = os_ver[1];
    if (! ereg(pattern:"^5([^0-9]|$)", string:os_ver)) audit(AUDIT_OS_NOT, "Red Hat 5.x", "Red Hat " + os_ver);
    
    if (!get_kb_item("Host/RedHat/rpm-list")) audit(AUDIT_PACKAGE_LIST_MISSING);
    
    cpu = get_kb_item("Host/cpu");
    if (isnull(cpu)) audit(AUDIT_UNKNOWN_ARCH);
    if ("x86_64" >!< cpu && cpu !~ "^i[3-6]86$" && "s390" >!< cpu) audit(AUDIT_LOCAL_CHECKS_NOT_IMPLEMENTED, "Red Hat", cpu);
    
    yum_updateinfo = get_kb_item("Host/RedHat/yum-updateinfo");
    if (!empty_or_null(yum_updateinfo)) 
    {
      rhsa = "RHSA-2014:1824";
      yum_report = redhat_generate_yum_updateinfo_report(rhsa:rhsa);
      if (!empty_or_null(yum_report))
      {
        security_report_v4(
          port       : 0,
          severity   : SECURITY_HOLE,
          extra      : yum_report 
        );
        exit(0);
      }
      else
      {
        audit_message = "affected by Red Hat security advisory " + rhsa;
        audit(AUDIT_OS_NOT, audit_message);
      }
    }
    else
    {
      flag = 0;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-bcmath-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-bcmath-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-bcmath-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-cli-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-cli-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-cli-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-common-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-common-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-common-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-dba-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-dba-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-dba-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-debuginfo-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-debuginfo-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-debuginfo-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-devel-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-devel-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-devel-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-gd-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-gd-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-gd-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-imap-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-imap-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-imap-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-ldap-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-ldap-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-ldap-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-mbstring-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-mbstring-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-mbstring-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-mysql-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-mysql-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-mysql-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-ncurses-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-ncurses-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-ncurses-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-odbc-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-odbc-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-odbc-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-pdo-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-pdo-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-pdo-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-pgsql-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-pgsql-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-pgsql-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-snmp-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-snmp-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-snmp-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-soap-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-soap-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-soap-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-xml-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-xml-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-xml-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"i386", reference:"php-xmlrpc-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"s390x", reference:"php-xmlrpc-5.1.6-45.el5_11")) flag++;
      if (rpm_check(release:"RHEL5", cpu:"x86_64", reference:"php-xmlrpc-5.1.6-45.el5_11")) flag++;
    
      if (flag)
      {
        security_report_v4(
          port       : 0,
          severity   : SECURITY_HOLE,
          extra      : rpm_report_get() + redhat_report_package_caveat()
        );
        exit(0);
      }
      else
      {
        tested = pkg_tests_get();
        if (tested) audit(AUDIT_PACKAGE_NOT_AFFECTED, tested);
        else audit(AUDIT_PACKAGE_NOT_INSTALLED, "php / php-bcmath / php-cli / php-common / php-dba / php-debuginfo / etc");
      }
    }
    
  • NASL familyCentOS Local Security Checks
    NASL idCENTOS_RHSA-2014-1824.NASL
    descriptionUpdated php packages that fix three security issues are now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A buffer overflow flaw was found in the Exif extension. A specially crafted JPEG or TIFF file could cause a PHP application using the exif_thumbnail() function to crash or, possibly, execute arbitrary code with the privileges of the user running that PHP application. (CVE-2014-3670) A stack-based buffer overflow flaw was found in the way the xmlrpc extension parsed dates in the ISO 8601 format. A specially crafted XML-RPC request or response could possibly cause a PHP application to crash. (CVE-2014-8626) An integer overflow flaw was found in the way custom objects were unserialized. Specially crafted input processed by the unserialize() function could cause a PHP application to crash. (CVE-2014-3669) All php users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, the httpd daemon must be restarted for the update to take effect.
    last seen2020-06-01
    modified2020-06-02
    plugin id78895
    published2014-11-07
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/78895
    titleCentOS 5 : php (CESA-2014:1824)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    # The descriptive text and package checks in this plugin were  
    # extracted from Red Hat Security Advisory RHSA-2014:1824 and 
    # CentOS Errata and Security Advisory 2014:1824 respectively.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(78895);
      script_version("1.13");
      script_cvs_date("Date: 2020/01/06");
    
      script_cve_id("CVE-2014-3669", "CVE-2014-3670", "CVE-2014-8626");
      script_bugtraq_id(70611, 70665, 70928);
      script_xref(name:"RHSA", value:"2014:1824");
    
      script_name(english:"CentOS 5 : php (CESA-2014:1824)");
      script_summary(english:"Checks rpm output for the updated packages");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"The remote CentOS host is missing one or more security updates."
      );
      script_set_attribute(
        attribute:"description", 
        value:
    "Updated php packages that fix three security issues are now available
    for Red Hat Enterprise Linux 5.
    
    Red Hat Product Security has rated this update as having Important
    security impact. Common Vulnerability Scoring System (CVSS) base
    scores, which give detailed severity ratings, are available for each
    vulnerability from the CVE links in the References section.
    
    PHP is an HTML-embedded scripting language commonly used with the
    Apache HTTP Server.
    
    A buffer overflow flaw was found in the Exif extension. A specially
    crafted JPEG or TIFF file could cause a PHP application using the
    exif_thumbnail() function to crash or, possibly, execute arbitrary
    code with the privileges of the user running that PHP application.
    (CVE-2014-3670)
    
    A stack-based buffer overflow flaw was found in the way the xmlrpc
    extension parsed dates in the ISO 8601 format. A specially crafted
    XML-RPC request or response could possibly cause a PHP application to
    crash. (CVE-2014-8626)
    
    An integer overflow flaw was found in the way custom objects were
    unserialized. Specially crafted input processed by the unserialize()
    function could cause a PHP application to crash. (CVE-2014-3669)
    
    All php users are advised to upgrade to these updated packages, which
    contain backported patches to correct these issues. After installing
    the updated packages, the httpd daemon must be restarted for the
    update to take effect."
      );
      # https://lists.centos.org/pipermail/centos-announce/2014-November/020743.html
      script_set_attribute(
        attribute:"see_also",
        value:"http://www.nessus.org/u?78f3ff81"
      );
      script_set_attribute(attribute:"solution", value:"Update the affected php packages.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P");
      script_set_cvss_temporal_vector("CVSS2#E:U/RL:OF/RC:C");
      script_set_attribute(attribute:"cvss_score_source", value:"CVE-2014-3669");
      script_set_attribute(attribute:"exploitability_ease", value:"No known exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"false");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-bcmath");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-cli");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-common");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-dba");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-devel");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-gd");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-imap");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-ldap");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-mbstring");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-mysql");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-ncurses");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-odbc");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-pdo");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-pgsql");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-snmp");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-soap");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-xml");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:centos:centos:php-xmlrpc");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:centos:centos:5");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2014/10/29");
      script_set_attribute(attribute:"patch_publication_date", value:"2014/11/06");
      script_set_attribute(attribute:"plugin_publication_date", value:"2014/11/07");
      script_set_attribute(attribute:"generated_plugin", value:"current");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.");
      script_family(english:"CentOS Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/CentOS/release", "Host/CentOS/rpm-list");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("rpm.inc");
    
    
    if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    release = get_kb_item("Host/CentOS/release");
    if (isnull(release) || "CentOS" >!< release) audit(AUDIT_OS_NOT, "CentOS");
    os_ver = pregmatch(pattern: "CentOS(?: Linux)? release ([0-9]+)", string:release);
    if (isnull(os_ver)) audit(AUDIT_UNKNOWN_APP_VER, "CentOS");
    os_ver = os_ver[1];
    if (! preg(pattern:"^5([^0-9]|$)", string:os_ver)) audit(AUDIT_OS_NOT, "CentOS 5.x", "CentOS " + os_ver);
    
    if (!get_kb_item("Host/CentOS/rpm-list")) audit(AUDIT_PACKAGE_LIST_MISSING);
    
    
    cpu = get_kb_item("Host/cpu");
    if (isnull(cpu)) audit(AUDIT_UNKNOWN_ARCH);
    if ("x86_64" >!< cpu && cpu !~ "^i[3-6]86$") audit(AUDIT_LOCAL_CHECKS_NOT_IMPLEMENTED, "CentOS", cpu);
    
    
    flag = 0;
    if (rpm_check(release:"CentOS-5", reference:"php-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-bcmath-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-cli-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-common-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-dba-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-devel-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-gd-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-imap-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-ldap-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-mbstring-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-mysql-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-ncurses-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-odbc-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-pdo-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-pgsql-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-snmp-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-soap-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-xml-5.1.6-45.el5_11")) flag++;
    if (rpm_check(release:"CentOS-5", reference:"php-xmlrpc-5.1.6-45.el5_11")) flag++;
    
    
    if (flag)
    {
      security_report_v4(
        port       : 0,
        severity   : SECURITY_HOLE,
        extra      : rpm_report_get()
      );
      exit(0);
    }
    else
    {
      tested = pkg_tests_get();
      if (tested) audit(AUDIT_PACKAGE_NOT_AFFECTED, tested);
      else audit(AUDIT_PACKAGE_NOT_INSTALLED, "php / php-bcmath / php-cli / php-common / php-dba / php-devel / etc");
    }
    
  • NASL familyCGI abuses
    NASL idPHP_5_2_7.NASL
    descriptionAccording to its banner, the version of PHP installed on the remote host is prior to 5.2.7. It is, therefore, affected by multiple vulnerabilities : - There is a buffer overflow flaw in the bundled PCRE library that allows a denial of service attack. (CVE-2008-2371) - Multiple directory traversal vulnerabilities exist in functions such as
    last seen2020-06-01
    modified2020-06-02
    plugin id35043
    published2008-12-05
    reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/35043
    titlePHP 5 < 5.2.7 Multiple Vulnerabilities
  • NASL familyOracle Linux Local Security Checks
    NASL idORACLELINUX_ELSA-2014-1824.NASL
    descriptionFrom Red Hat Security Advisory 2014:1824 : Updated php packages that fix three security issues are now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A buffer overflow flaw was found in the Exif extension. A specially crafted JPEG or TIFF file could cause a PHP application using the exif_thumbnail() function to crash or, possibly, execute arbitrary code with the privileges of the user running that PHP application. (CVE-2014-3670) A stack-based buffer overflow flaw was found in the way the xmlrpc extension parsed dates in the ISO 8601 format. A specially crafted XML-RPC request or response could possibly cause a PHP application to crash. (CVE-2014-8626) An integer overflow flaw was found in the way custom objects were unserialized. Specially crafted input processed by the unserialize() function could cause a PHP application to crash. (CVE-2014-3669) All php users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, the httpd daemon must be restarted for the update to take effect.
    last seen2020-06-01
    modified2020-06-02
    plugin id78908
    published2014-11-07
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/78908
    titleOracle Linux 5 : php (ELSA-2014-1824)
  • NASL familyScientific Linux Local Security Checks
    NASL idSL_20141106_PHP_ON_SL5_X.NASL
    descriptionA buffer overflow flaw was found in the Exif extension. A specially crafted JPEG or TIFF file could cause a PHP application using the exif_thumbnail() function to crash or, possibly, execute arbitrary code with the privileges of the user running that PHP application. (CVE-2014-3670) A stack-based buffer overflow flaw was found in the way the xmlrpc extension parsed dates in the ISO 8601 format. A specially crafted XML-RPC request or response could possibly cause a PHP application to crash. (CVE-2014-8626) An integer overflow flaw was found in the way custom objects were unserialized. Specially crafted input processed by the unserialize() function could cause a PHP application to crash. (CVE-2014-3669) After installing the updated packages, the httpd daemon must be restarted for the update to take effect.
    last seen2020-03-18
    modified2014-11-10
    plugin id79082
    published2014-11-10
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/79082
    titleScientific Linux Security Update : php on SL5.x i386/x86_64 (20141106)

Redhat

advisories
  • bugzilla
    id1155607
    titleCVE-2014-8626 php: xmlrpc ISO8601 date format parsing buffer overflow
    oval
    OR
    • commentRed Hat Enterprise Linux must be installed
      ovaloval:com.redhat.rhba:tst:20070304026
    • AND
      • commentRed Hat Enterprise Linux 5 is installed
        ovaloval:com.redhat.rhba:tst:20070331005
      • OR
        • AND
          • commentphp-gd is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824001
          • commentphp-gd is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082018
        • AND
          • commentphp is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824003
          • commentphp is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082022
        • AND
          • commentphp-mbstring is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824005
          • commentphp-mbstring is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082014
        • AND
          • commentphp-odbc is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824007
          • commentphp-odbc is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082010
        • AND
          • commentphp-imap is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824009
          • commentphp-imap is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082004
        • AND
          • commentphp-ncurses is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824011
          • commentphp-ncurses is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082016
        • AND
          • commentphp-soap is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824013
          • commentphp-soap is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082034
        • AND
          • commentphp-common is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824015
          • commentphp-common is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082038
        • AND
          • commentphp-pgsql is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824017
          • commentphp-pgsql is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082028
        • AND
          • commentphp-ldap is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824019
          • commentphp-ldap is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082012
        • AND
          • commentphp-pdo is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824021
          • commentphp-pdo is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082026
        • AND
          • commentphp-xmlrpc is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824023
          • commentphp-xmlrpc is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082036
        • AND
          • commentphp-devel is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824025
          • commentphp-devel is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082020
        • AND
          • commentphp-mysql is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824027
          • commentphp-mysql is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082024
        • AND
          • commentphp-bcmath is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824029
          • commentphp-bcmath is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082006
        • AND
          • commentphp-snmp is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824031
          • commentphp-snmp is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082002
        • AND
          • commentphp-cli is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824033
          • commentphp-cli is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082030
        • AND
          • commentphp-xml is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824035
          • commentphp-xml is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082008
        • AND
          • commentphp-dba is earlier than 0:5.1.6-45.el5_11
            ovaloval:com.redhat.rhsa:tst:20141824037
          • commentphp-dba is signed with Red Hat redhatrelease key
            ovaloval:com.redhat.rhsa:tst:20070082032
    rhsa
    idRHSA-2014:1824
    released2014-11-06
    severityImportant
    titleRHSA-2014:1824: php security update (Important)
  • rhsa
    idRHSA-2014:1825
rpms
  • php-0:5.1.6-45.el5_11
  • php-bcmath-0:5.1.6-45.el5_11
  • php-cli-0:5.1.6-45.el5_11
  • php-common-0:5.1.6-45.el5_11
  • php-dba-0:5.1.6-45.el5_11
  • php-debuginfo-0:5.1.6-45.el5_11
  • php-devel-0:5.1.6-45.el5_11
  • php-gd-0:5.1.6-45.el5_11
  • php-imap-0:5.1.6-45.el5_11
  • php-ldap-0:5.1.6-45.el5_11
  • php-mbstring-0:5.1.6-45.el5_11
  • php-mysql-0:5.1.6-45.el5_11
  • php-ncurses-0:5.1.6-45.el5_11
  • php-odbc-0:5.1.6-45.el5_11
  • php-pdo-0:5.1.6-45.el5_11
  • php-pgsql-0:5.1.6-45.el5_11
  • php-snmp-0:5.1.6-45.el5_11
  • php-soap-0:5.1.6-45.el5_11
  • php-xml-0:5.1.6-45.el5_11
  • php-xmlrpc-0:5.1.6-45.el5_11
  • php-0:4.3.9-3.38.el4
  • php-debuginfo-0:4.3.9-3.38.el4
  • php-devel-0:4.3.9-3.38.el4
  • php-domxml-0:4.3.9-3.38.el4
  • php-gd-0:4.3.9-3.38.el4
  • php-imap-0:4.3.9-3.38.el4
  • php-ldap-0:4.3.9-3.38.el4
  • php-mbstring-0:4.3.9-3.38.el4
  • php-mysql-0:4.3.9-3.38.el4
  • php-ncurses-0:4.3.9-3.38.el4
  • php-odbc-0:4.3.9-3.38.el4
  • php-pear-0:4.3.9-3.38.el4
  • php-pgsql-0:4.3.9-3.38.el4
  • php-snmp-0:4.3.9-3.38.el4
  • php-xmlrpc-0:4.3.9-3.38.el4