PHP Multiple Unspecified Vulnerabilities
BID:17843
CVE-2006-3016 | CVE-2006-3017 | CVE-2006-3018 |Info
PHP Multiple Unspecified Vulnerabilities
| Bugtraq ID: | 17843 |
| Class: | Unknown |
| CVE: |
CVE-2006-3017 CVE-2006-3018 CVE-2006-3016 |
| Remote: | Yes |
| Local: | No |
| Published: | May 04 2006 12:00AM |
| Updated: | Jan 15 2007 07:40PM |
| Credit: | These issues were disclosed by the vendor. Stefan Esser discovered the 'unset()' vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 x86 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 2.0 TransSoft Broker FTP Server 8.0 Simple Machines SMF 1.1 rc1 Simple Machines SMF 1.0.7 Simple Machines SMF 1.0.6 Simple Machines SMF 1.0.5 Simple Machines SMF 1.0.4 Simple Machines SMF 1.0.2 Simple Machines SMF 1.0 -beta5p Simple Machines SMF 1.0 -beta4p Simple Machines SMF 1.0 -beta4.1 SGI ProPack 3.0 SP6 rPath rPath Linux 1 Redhat Stronghold for Enterprise Linux 0 Redhat Stronghold 4.0 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 PmWiki PmWiki 2.1.19 PHP PHP/FI 2.0 b10 PHP PHP/FI 2.0 PHP PHP/FI 1.0 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 4.4.2 PHP PHP 4.4.1 PHP PHP 4.4 .0 PHP PHP 4.3.11 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.2 -dev PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 pl1 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 pl2 PHP PHP 4.0.1 pl1 PHP PHP 4.0.1 PHP PHP 4.0 0 PHP PHP 3.0.18 PHP PHP 3.0.17 PHP PHP 3.0.16 PHP PHP 3.0.15 PHP PHP 3.0.14 PHP PHP 3.0.13 PHP PHP 3.0.12 PHP PHP 3.0.11 PHP PHP 3.0.10 PHP PHP 3.0.9 PHP PHP 3.0.8 PHP PHP 3.0.7 PHP PHP 3.0.6 PHP PHP 3.0.5 PHP PHP 3.0.4 PHP PHP 3.0.3 PHP PHP 3.0.2 PHP PHP 3.0.1 PHP PHP 3.0 0 PHP PHP 3.0 .16 PHP PHP 3.0 .13 PHP PHP 3.0 .12 PHP PHP 3.0 .11 PHP PHP 3.0 .10 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 e107 e107 website system 0.7.5 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Avaya S8710 R2.0.1 Avaya S8710 R2.0.0 Avaya S8700 R2.0.1 Avaya S8700 R2.0.0 Avaya S8500 R2.0.1 Avaya S8500 R2.0.0 Avaya S8300 R2.0.1 Avaya S8300 R2.0.0 Avaya S8300 0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server Avaya Message Networking Avaya Intuity LX Avaya Integrated Management Avaya CVLAN Avaya Converged Communications Server 2.0 |
| Not Vulnerable: |
Simple Machines SMF 1.1 rc3 Simple Machines SMF 1.0.8 PHP PHP 5.1.3 |
Discussion
PHP Multiple Unspecified Vulnerabilities
PHP is vulnerable to multiple unspecified vulnerabilities ranging from buffer-overflow to cross-site scripting issues.
The precise nature of these vulnerabilities is currently not known; this BID will be updated as more information becomes available.
Some of the issues discussed may be related to other BIDs regarding PHP vulnerabilities.
PHP is vulnerable to multiple unspecified vulnerabilities ranging from buffer-overflow to cross-site scripting issues.
The precise nature of these vulnerabilities is currently not known; this BID will be updated as more information becomes available.
Some of the issues discussed may be related to other BIDs regarding PHP vulnerabilities.
Exploit / POC
PHP Multiple Unspecified Vulnerabilities
An exploit has been released for e107 that demonstrates the 'zend_hash_del_key_or_index()' function vulnerability.
Attackers may exploit some of these issues through a web client.
An exploit has been released for e107 that demonstrates the 'zend_hash_del_key_or_index()' function vulnerability.
Attackers may exploit some of these issues through a web client.
Solution / Fix
PHP Multiple Unspecified Vulnerabilities
Solution:
The vendor has addressed these issues in version 5.1.3 and later.
Please see the referenced advisories for information on obtaining and applying fixes.
Simple Machines SMF 1.0 -beta4.1
Simple Machines SMF 1.0 -beta4p
Simple Machines SMF 1.0.2
PHP PHP/FI 2.0 b10
PHP PHP 3.0 0
PHP PHP 3.0 .10
PHP PHP 3.0 .12
PHP PHP 3.0 .13
PHP PHP 3.0 .11
PHP PHP 3.0.10
PHP PHP 3.0.11
PHP PHP 3.0.13
PHP PHP 3.0.15
PHP PHP 3.0.17
PHP PHP 3.0.2
PHP PHP 3.0.3
PHP PHP 3.0.4
PHP PHP 3.0.5
PHP PHP 3.0.9
PHP PHP 4.0 0
PHP PHP 4.0.1
PHP PHP 4.0.1 pl2
PHP PHP 4.0.2
PHP PHP 4.0.3 pl1
PHP PHP 4.0.3
PHP PHP 4.0.5
PHP PHP 4.0.7 RC1
PHP PHP 4.0.7 RC2
PHP PHP 4.0.7
PHP PHP 4.1 .0
PHP PHP 4.2 -dev
PHP PHP 4.2.1
PHP PHP 4.3
PHP PHP 4.3.2
PHP PHP 4.3.3
PHP PHP 4.3.4
PHP PHP 4.3.5
PHP PHP 4.3.6
PHP PHP 4.3.8
PHP PHP 4.3.9
PHP PHP 4.4.1
PHP PHP 4.4.2
PHP PHP 5.0 .0
PHP PHP 5.0 candidate 1
PHP PHP 5.0.1
PHP PHP 5.0.2
PHP PHP 5.0.4
PHP PHP 5.1
PHP PHP 5.1.1
PHP PHP 5.1.3 -RC1
Solution:
The vendor has addressed these issues in version 5.1.3 and later.
Please see the referenced advisories for information on obtaining and applying fixes.
Simple Machines SMF 1.0 -beta4.1
-
Simple Machines SMF 1.0.8 and 1.1.0 rc3 - install
http://www.simplemachines.org/download/
Simple Machines SMF 1.0 -beta4p
-
Simple Machines SMF 1.0.8 and 1.1.0 rc3 - install
http://www.simplemachines.org/download/
Simple Machines SMF 1.0.2
-
Simple Machines SMF 1.0.8 and 1.1.0 rc3 - install
http://www.simplemachines.org/download/
PHP PHP/FI 2.0 b10
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0 0
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0 .10
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0 .12
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0 .13
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0 .11
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0.10
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0.11
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0.13
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0.15
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0.17
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0.2
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0.3
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0.4
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0.5
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 3.0.9
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.0 0
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.0.1
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.0.1 pl2
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.0.2
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.0.3 pl1
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.0.3
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.0.5
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.0.7 RC1
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.0.7 RC2
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.0.7
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.1 .0
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.2 -dev
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.2.1
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.3
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.3.2
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.3.3
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.3.4
-
Mandriva lib64php_common432-4.3.4-4.18.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
Mandriva libphp_common432-4.3.4-4.18.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-cgi-4.3.4-4.18.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-cgi-4.3.4-4.18.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-cli-4.3.4-4.18.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-cli-4.3.4-4.18.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-gd-4.3.4-1.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-gd-4.3.4-1.3.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-imap-4.3.4-1.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-imap-4.3.4-1.3.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php432-devel-4.3.4-4.18.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php432-devel-4.3.4-4.18.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.3.5
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.3.6
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.3.8
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.3.9
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.4.1
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 4.4.2
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 5.0 .0
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 5.0 candidate 1
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 5.0.1
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 5.0.2
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 5.0.4
-
Mandriva lib64php5_common5-5.0.4-9.12.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
Mandriva libphp5_common5-5.0.4-9.12.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-cgi-5.0.4-9.12.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-cgi-5.0.4-9.12.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-cli-5.0.4-9.12.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-cli-5.0.4-9.12.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-curl-5.0.4-1.3.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-curl-5.0.4-1.3.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-devel-5.0.4-9.12.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-devel-5.0.4-9.12.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-fcgi-5.0.4-9.12.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-fcgi-5.0.4-9.12.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-imap-5.0.4-2.3.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva php-imap-5.0.4-2.3.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads -
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 5.1
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 5.1.1
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
PHP PHP 5.1.3 -RC1
-
PHP php-5.1.3.tar.gz
http://www.php.net/get/php-5.1.3.tar.gz/from/a/mirror
References
PHP Multiple Unspecified Vulnerabilities
References:
References:
- ASA-2006-175 - php security update (RHSA-2006-0568) (Avaya)
- ASA-2006-179 - php security update (RHSA-2006-0567) (Avaya)
- PHP 5.1.3 Release (PHP)
- PHP Website (PHP Website)
- PmWiki <= 2.1.19 Zend_Hash_Del_Key_Or_Index/remote commands execution exploit (rgod)
- RHSA-2006:0549-7 - php security update for Stronghold (Red Hat)
- RHSA-2006:0567-7 - php security update (Red Hat)
- RHSA-2006:0682-6 - php security update (RedHat)
- Zend_Hash_Del_Key_Or_Index PHP Local (rgod)
- Zend_Hash_Del_Key_Or_Index PHP Lock (rgod)
- Zend_Hash_Del_Key_Or_Index Vulnerability (Stefan Esser)
- PHP: Zend_Hash_Del_Key_Or_Index Vulnerability (Stefan Esser
) - Simple Machines Forum <=1.1RC2 unset() vulnerabilities ([email protected])
- ASA-2006-222 - php security update (RHSA-2006-0669) (Avaya)
- RHSA-2006:0736-4 - php security update for Stronghold (RedHat)