Fury-Tech Logo
Home  News  Articles  Reviews  Guides  Resources  Forums 
Fury-Tech // Technology news, hardware and game reviews, guides, articles, and resources   
Search:



There are currently 0 members and 83 guests browsing on Fury-Tech.


Join our community in the tech forums for uncut technology discussion.
Home > News > PHP Security Advisory: CGI vulnerability in PHP version 4.3.0

<< Back to Today's Tech News

PHP Security Advisory: CGI vulnerability in PHP version 4.3.0


Posted by Tekime on 2003-02-19 09:03:20

The PHP Group has learned of a serious security vulnerability in the CGI SAPI of PHP version 4.3.0.

Description
PHP contains code for preventing direct access to the CGI binary with configure option "--enable-force-cgi-redirect" and php.ini option "cgi.force_redirect". In PHP 4.3.0 there is a bug which renders these options useless.

NOTE: This bug does NOT affect any of the other SAPI modules.
(such as the Apache or ISAPI modules, etc.)

Impact
Anyone with access to websites hosted on a web server which employs the CGI module may exploit this vulnerability to gain access to any file readable by the user under which the webserver runs.

A remote attacker could also trick PHP into executing arbitrary PHP code if attacker is able to inject the code into files accessible by the CGI. This could be for example the web server access-logs.

Solution
The PHP Group has released a new PHP version, 4.3.1, which incorporates a fix for the vulnerability. All users of affected PHP versions are encouraged to upgrade to this latest version. The downloads web site at

http://www.php.net/downloads.php
has the new 4.3.1 source tarballs, Windows binaries and source patch from 4.3.0 available for download. You will only need to upgrade if you're using the CGI module of PHP 4.3.0. There are no other bugfixes contained in this release.

Read More at PHP.net

Article Comments


Post a comment on this page
Name You must register or login to post comments.
Subject
Comment

Join our community in the tech forums for uncut technology discussion.



©2007 Fury-Tech | Tech News, Hardware Reviews, Forums, Guides, and more.

Web Hosting by Intavant

Tech News | Articles | Reviews | Guides | Resources | Tech Forums