PHP stream_wrapper_register() Function Denial of Service Vulnerability
BID:26426
Info
PHP stream_wrapper_register() Function Denial of Service Vulnerability
| Bugtraq ID: | 26426 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6039 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 13 2007 12:00AM |
| Updated: | Dec 18 2007 08:04PM |
| Credit: | laurent gaffie is credited with the discovery of this vulnerability. |
| Vulnerable: |
PHP PHP 5.2.5 PHP PHP 5.2.4 PHP PHP 5.2.3 PHP PHP 5.2.2 PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.2 |
| Not Vulnerable: | |
Discussion
PHP stream_wrapper_register() Function Denial of Service Vulnerability
PHP is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
PHP 5.2.5 and prior versions are vulnerable.
PHP is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
PHP 5.2.5 and prior versions are vulnerable.
Exploit / POC
PHP stream_wrapper_register() Function Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
PHP stream_wrapper_register() Function Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHP stream_wrapper_register() Function Denial of Service Vulnerability
References:
References: