Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default Is this serious? PHP <= 4.4.3 / 5.1.4 (objIndex) Local Buffer Overflow Exploit PoC

    Is this serious?
    PHP <= 4.4.3 / 5.1.4 (objIndex) Local Buffer Overflow Exploit PoC

    I have php 4.4.2, am I at risk?
    # php -v
    PHP 4.4.2

  2. #2
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Just add sscanf to your php.ini disable_functions line, and you should be fine. It's not a very commonly used function.

    This vulnerability also exists in PHP 4.4.3. Nevertheless you should upgrade to PHP 4.4.3, since several other security issues were fixed in that version.

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default

    Have you been able to get that exploit to work?

    I keep getting a segmentation fault

    [/tmp]# php sscanf.php
    Segmentation fault

  4. #4

  5. #5
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Vulnearability is fixed in CVS.
    Shame PHP hasn't mentioned when they're going to bother actually releasing a fixed version instead of leaving it to twiddle its thumbs in CVS, especially since it was reported to them so long ago.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  6. #6
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default

    So it always gives a segmentation fault? Its not a security risk then, no?

Similar Threads & Tags
Similar threads

  1. Replies: 3
    Last Post: 08-30-2010, 02:02 PM
  2. Buffer Overflow Attemp?
    By fizz in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-07-2004, 10:54 AM
  3. OpenSSH Buffer Exploit
    By pirania1 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-16-2003, 01:48 PM
  4. CERT Advisory CA-2002-19 Buffer Overflow in Multiple DNS Res
    By andyf in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 07-01-2002, 03:35 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube