PHP4 Ovrimos Extension Code Execution Vulnerability
BID:22833
Info
PHP4 Ovrimos Extension Code Execution Vulnerability
| Bugtraq ID: | 22833 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-1379 CVE-2007-1378 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 06 2007 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | Stefan Esser disclosed this vulnerability. |
| Vulnerable: |
PHP PHP 4.4.4 PHP PHP 4.4.3 PHP PHP 4.4.2 PHP PHP 4.4.1 PHP PHP 4.4 .0 PHP PHP 4.3.11 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.2 -dev PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 pl1 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 pl2 PHP PHP 4.0.1 pl1 PHP PHP 4.0.1 PHP PHP 4.0 0 PHP PHP 3.0.18 PHP PHP 3.0.17 PHP PHP 3.0.16 PHP PHP 3.0.15 PHP PHP 3.0.14 PHP PHP 3.0.13 PHP PHP 3.0.12 PHP PHP 3.0.11 PHP PHP 3.0.10 PHP PHP 3.0.9 PHP PHP 3.0.8 PHP PHP 3.0.7 PHP PHP 3.0.6 PHP PHP 3.0.5 PHP PHP 3.0.4 PHP PHP 3.0.3 PHP PHP 3.0.2 PHP PHP 3.0.1 PHP PHP 3.0 0 PHP PHP 3.0 .16 PHP PHP 3.0 .13 PHP PHP 3.0 .12 PHP PHP 3.0 .11 PHP PHP 3.0 .10 |
| Not Vulnerable: |
PHP PHP 4.4.5 |
Discussion
PHP4 Ovrimos Extension Code Execution Vulnerability
PHP4 is prone to a code-execution vulnerability due to a design error in a vulnerable extension.
For this vulnerability to occur, the non-maintained 'Ovrimos SQL Server Extension' must have been compiled into the targetted PHP implementation.
Successful exploits may allow an attacker to execute arbitrary code in the context of the affected application. Failed exploits would likely crash PHP.
PHP versions prior to 4.4.5 with a compiled 'Ovrimos SQL Server Extension' are vulnerable to this issue.
PHP4 is prone to a code-execution vulnerability due to a design error in a vulnerable extension.
For this vulnerability to occur, the non-maintained 'Ovrimos SQL Server Extension' must have been compiled into the targetted PHP implementation.
Successful exploits may allow an attacker to execute arbitrary code in the context of the affected application. Failed exploits would likely crash PHP.
PHP versions prior to 4.4.5 with a compiled 'Ovrimos SQL Server Extension' are vulnerable to this issue.
Exploit / POC
PHP4 Ovrimos Extension Code Execution Vulnerability
An attacker may exploit this issue using commonly available tools and commands.
An attacker may exploit this issue using commonly available tools and commands.
Solution / Fix
PHP4 Ovrimos Extension Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHP4 Ovrimos Extension Code Execution Vulnerability
References:
References:
- PHP Homepage (PHP)
- MOPB-13-2007:PHP 4 Ovrimos Extension Multiple Vulnerabilities (PHP-Security)