PHP .Htaccess Safe_Mode and Open_Basedir Restriction-Bypass Vulnerability
BID:24661
Info
PHP .Htaccess Safe_Mode and Open_Basedir Restriction-Bypass Vulnerability
| Bugtraq ID: | 24661 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3378 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2007 12:00AM |
| Updated: | May 20 2008 05:54PM |
| Credit: | Maksymilian Arciemowicz discovered these issues. |
| Vulnerable: |
Trustix Secure Linux 3.0.5 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Operating System Enterprise Server 2.0 Slackware Linux 12.0 Slackware Linux -current rPath rPath Linux 1 Redhat Fedora Core7 PHP PHP 5.2.3 PHP PHP 5.2.2 PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 4.4.7 PHP PHP 4.4.6 PHP PHP 4.4.5 PHP PHP 4.4.4 PHP PHP 4.4.3 PHP PHP 4.4.2 PHP PHP 4.4.1 PHP PHP 4.4 .0 PHP PHP 4.3.11 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.2 -dev PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 pl1 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 pl2 PHP PHP 4.0.1 pl1 PHP PHP 4.0.1 PHP PHP 4.0 0 PHP PHP 5.2 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Gentoo Linux Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.4.11 Apple Mac OS X 10.4.11 |
| Not Vulnerable: |
PHP PHP 5.2.4 |
Discussion
PHP .Htaccess Safe_Mode and Open_Basedir Restriction-Bypass Vulnerability
PHP is prone to a 'safe_mode' and 'open_basedir' restriction-bypass vulnerability. Successful exploits could allow an attacker to write files in unauthorized locations.
These vulnerabilities would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, with the 'safe_mode' and 'open_basedir' restrictions assumed to isolate the users from each other.
This issue is reported to affect PHP 5.2.3 and 4.4.7; previous versions may also be vulnerable.
PHP is prone to a 'safe_mode' and 'open_basedir' restriction-bypass vulnerability. Successful exploits could allow an attacker to write files in unauthorized locations.
These vulnerabilities would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, with the 'safe_mode' and 'open_basedir' restrictions assumed to isolate the users from each other.
This issue is reported to affect PHP 5.2.3 and 4.4.7; previous versions may also be vulnerable.
Exploit / POC
PHP .Htaccess Safe_Mode and Open_Basedir Restriction-Bypass Vulnerability
To exploit these issues, an attacker may use system commands and standard PHP code. The attacker must also be able to write to a '.htaccess' file. The "AllowOverride Options" and "AllowOverride All" privileges must be set in Apache configurations.
The discoverer of this issue states that he will release an exploit on June 29, 2007.
To exploit these issues, an attacker may use system commands and standard PHP code. The attacker must also be able to write to a '.htaccess' file. The "AllowOverride Options" and "AllowOverride All" privileges must be set in Apache configurations.
The discoverer of this issue states that he will release an exploit on June 29, 2007.
Solution / Fix
PHP .Htaccess Safe_Mode and Open_Basedir Restriction-Bypass Vulnerability
Solution:
The vendor has released PHP 5.2.4 to address this issue. Please see the referenced advisories for more information.
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X Server 10.5.2
PHP PHP 5.2.3
Solution:
The vendor has released PHP 5.2.4 to address this issue. Please see the referenced advisories for more information.
Apple Mac OS X 10.4.11
-
Apple SecUpd2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002PPC.dmg -
Apple SecUpd2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002Univ.dmg
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002PPC.dmg -
Apple SecUpdSrvr2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002Univ.dmg
Apple Mac OS X Server 10.5.2
-
Apple SecUpdSrvr2008-002.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002.dmg
PHP PHP 5.2.3
-
PHP PHP 5.2.4 Complete Source Code
http://www.php.net/get/php-5.2.4.tar.gz/from/a/mirror
References
PHP .Htaccess Safe_Mode and Open_Basedir Restriction-Bypass Vulnerability
References:
References:
- PHP 5.2.4 Release Announcement (PHP)
- PHP Project (PHP)
- PHP Version 5.2.4 Changelog (PHP)
- [security bulletin] HPSBUX02332 SSRT080056 rev.2 - HP-UX Running Apache With PHP ([email protected])
- PHP 4/5 htaccess safemode and open_basedir Bypass (Maksymilian Arciemowicz)
- TSLSA-2007-0026 - multi (Trustix)
- HPSBUX02308 SSRT080010 rev.1 - HP-UX Running Apache, Remote Execution of Arbitra (HP)
- PHP 5.2.3 PHP 4.4.7, htaccess safemode and open_basedir Bypass (SecurityReason)