Release date:
Updated on:
Affected Systems:
PHP 5.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 47545
PHP, an abbreviated name for nesting, is the abbreviation of the English Super Text preprocessing language (PHP: Hypertext Preprocessor.
PHP "phar/tar. c "there is a heap buffer overflow vulnerability in implementation. Remote attackers can exploit this vulnerability to run arbitrary code in PHP processes to bypass the objective security restrictions or gain elevation of permissions.
<* Source: Alexander Gavrun
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
<? Php if (! Extension_loaded ("phar") die ("skip ");
$ Phar = new Phar (dirname (_ FILE _). '/poc.phar.tar ');
?>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PHP
---
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.php.net