PHP4 Readfile Denial Of Service Vulnerability
BID:12665
Info
PHP4 Readfile Denial Of Service Vulnerability
| Bugtraq ID: | 12665 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 25 2005 12:00AM |
| Updated: | Feb 25 2005 12:00AM |
| Credit: | This issue was announced by SuSE. It is not known who originally discovered this issue. |
| Vulnerable: |
SuSE Linux Enterprise Server 9 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.2 -dev PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 pl1 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 pl2 PHP PHP 4.0.1 pl1 PHP PHP 4.0.1 PHP PHP 4.0 0 |
| Not Vulnerable: | |
Discussion
PHP4 Readfile Denial Of Service Vulnerability
PHP4 is reported prone to a denial of service vulnerability. It is reported that the PHP 'readfile()' function may be utilized to trigger this issue.
An attacker that has access to a PHP enabled web host may exploit this vulnerability to crash the HTTP server that is incorporating the vulnerable PHP module.
PHP4 is reported prone to a denial of service vulnerability. It is reported that the PHP 'readfile()' function may be utilized to trigger this issue.
An attacker that has access to a PHP enabled web host may exploit this vulnerability to crash the HTTP server that is incorporating the vulnerable PHP module.
Exploit / POC
PHP4 Readfile Denial Of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PHP4 Readfile Denial Of Service Vulnerability
Solution:
SuSE has released Security Summary Report SUSE-SR:2005:006 to address this and other issues. Please see the referenced advisory for details on obtaining and applying fixes.
PHP PHP 4.3.3
PHP PHP 4.3.4
Solution:
SuSE has released Security Summary Report SUSE-SR:2005:006 to address this and other issues. Please see the referenced advisory for details on obtaining and applying fixes.
PHP PHP 4.3.3
-
SuSE apache2-mod_php4-4.3.3-185.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/apache2-mod_php4- 4.3.3-185.i586.rpm -
SuSE apache2-mod_php4-4.3.3-185.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/apache2-mod_p hp4-4.3.3-185.x86_64.rpm -
SuSE mod_php4-4.3.3-185.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/mod_php4-4.3.3-18 5.i586.rpm -
SuSE mod_php4-4.3.3-185.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/mod_php4-4.3. 3-185.x86_64.rpm -
SuSE mod_php4-aolserver-4.3.3-185.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/mod_php4-aolserve r-4.3.3-185.i586.rpm -
SuSE mod_php4-aolserver-4.3.3-185.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/mod_php4-aols erver-4.3.3-185.x86_64.rpm -
SuSE mod_php4-core-4.3.3-185.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/mod_php4-core-4.3 .3-185.i586.rpm -
SuSE mod_php4-core-4.3.3-185.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/mod_php4-core -4.3.3-185.x86_64.rpm -
SuSE mod_php4-servlet-4.3.3-185.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/mod_php4-servlet- 4.3.3-185.i586.rpm -
SuSE mod_php4-servlet-4.3.3-185.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/mod_php4-serv let-4.3.3-185.x86_64.rpm
PHP PHP 4.3.4
-
SuSE apache2-mod_php4-4.3.4-43.25.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/apache2-mod_php4- 4.3.4-43.25.i586.rpm -
SuSE apache2-mod_php4-4.3.4-43.25.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/apache2-mod_p hp4-4.3.4-43.25.x86_64.rpm -
SuSE mod_php4-core-4.3.4-43.25.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/mod_php4-core-4.3 .4-43.25.i586.rpm -
SuSE mod_php4-core-4.3.4-43.25.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/mod_php4-core -4.3.4-43.25.x86_64.rpm -
SuSE mod_php4-servlet-4.3.4-43.25.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/mod_php4-servlet- 4.3.4-43.25.i586.rpm -
SuSE mod_php4-servlet-4.3.4-43.25.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/mod_php4-serv let-4.3.4-43.25.x86_64.rpm -
SuSE php4-4.3.4-43.25.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/php4-4.3.4-43.25. i586.rpm -
SuSE php4-4.3.4-43.25.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/php4-4.3.4-43 .25.x86_64.rpm -
SuSE php4-imap-4.3.4-43.25.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/php4-imap-4.3.4-4 3.25.i586.rpm -
SuSE php4-imap-4.3.4-43.25.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/php4-imap-4.3 .4-43.25.x86_64.rpm -
SuSE php4-mysql-4.3.4-43.25.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/php4-mysql-4.3.4- 43.25.i586.rpm -
SuSE php4-mysql-4.3.4-43.25.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/php4-mysql-4. 3.4-43.25.x86_64.rpm -
SuSE php4-recode-4.3.4-43.25.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/php4-recode-4.3.4 -43.25.i586.rpm -
SuSE php4-recode-4.3.4-43.25.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/php4-recode-4 .3.4-43.25.x86_64.rpm -
SuSE php4-servlet-4.3.4-43.25.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/php4-servlet-4.3. 4-43.25.i586.rpm -
SuSE php4-servlet-4.3.4-43.25.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/php4-servlet- 4.3.4-43.25.x86_64.rpm -
SuSE php4-session-4.3.4-43.25.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/php4-session-4.3. 4-43.25.i586.rpm -
SuSE php4-session-4.3.4-43.25.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/php4-session- 4.3.4-43.25.x86_64.rpm -
SuSE php4-wddx-4.3.4-43.25.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/php4-wddx-4.3.4-4 3.25.i586.rpm -
SuSE php4-wddx-4.3.4-43.25.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/php4-wddx-4.3 .4-43.25.x86_64.rpm