SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Generic)  >  Php Vendors:  PHP Group
PHP zend_hash_del_key_or_index() May Let Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1016649
SecurityTracker URL:  http://securitytracker.com/id?1016649
CVE Reference:  CVE-2006-3017   (Links to External Site)
OSVDB Reference:  25255   (Links to External Site)
Updated:  Jan 30 2007
Original Entry Date:  Aug 8 2006
Impact:  Execution of arbitrary code via network, User access via network
Fix Available:  Yes   Exploit Included:  Yes   Vendor Confirmed:  Yes  
Version(s): prior to 4.4.3 and 5.1.4
Description:  A vulnerability was reported in PHP in the zend_hash_del_key_or_index() function. A remote user may be able to execute arbitrary code on the target system.

The zend_hash_del_key_or_index() function does not correctly delete bucket elements in a hash table. When a numeric index hash value is the same as an alphanumeric index hash value, the system may delete the wrong element in the array. Depending on the PHP functions used by the target PHP application, this may allow arbitrary code to be executed.

PHP functions that use the Zend hash table implementation are affected. In particular, the unset() function is affected and may not properly unset variables.

Applications such as miniBB, phpBB, and Wordpress are affected.

The original advisory is available at:

http://www.hardened-php.net/hphp/zend_hash_del_key_or_index_vulnerability. html

Stefan Esser reported this vulnerability.

Impact:  A remote user can execute arbitrary code on the target system.
Solution:  The vendor has issued a fixed version (4.4.3 and 5.1.4), available at:

http://www.php.net/downloads.php

Vendor URL:  www.php.net/ (Links to External Site)
Cause:  State error
Underlying OS:  Linux (Any), UNIX (Any), Windows (Any)
Reported By:  Stefan Esser <sesser@hardened-php.net>
Message History:   None.


 Source Message Contents

Date:  Sun, 06 Aug 2006 19:47:39 +0200
From:  Stefan Esser <sesser@hardened-php.net>
Subject:  PHP: Zend_Hash_Del_Key_Or_Index Vulnerability

 
Hello,

word about this vulnerability is out for several weeks (or months). Because of this I spare you the
advisory and only point you to my little article describing what exactly this vulnerability is,
that I disclosed to the PHP project 6 months ago:

The rating for this vulnerability should be: Very Critical

http://www.hardened-php.net/hphp/zend_hash_del_key_or_index_vulnerability.html

Greets,
Stefan Esser


 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2006, SecurityGlobal.net LLC