PHP HTTP POST Incorrect MIME Header Parsing Vulnerability
BID:5278
Info
PHP HTTP POST Incorrect MIME Header Parsing Vulnerability
| Bugtraq ID: | 5278 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 22 2002 12:00AM |
| Updated: | Jul 22 2002 12:00AM |
| Credit: | Discovery credited to e-matters Security <[email protected]>. |
| Vulnerable: |
PHP PHP 4.2.1 PHP PHP 4.2 .0 |
| Not Vulnerable: |
PHP PHP 4.2.2 PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 PHP PHP 4.0 0 |
Discussion
PHP HTTP POST Incorrect MIME Header Parsing Vulnerability
A vulnerability has been reported for PHP versions 4.2.0 and 4.2.1. It is possible for a remote attacker to cause the PHP interpreter to crash the web server on a vulnerable system and execute malicious, attacker supplied code.
The vulnerability is the result of the PHP interpreter incorrectly parsing MIME headers when HTTP POST commands are received. When PHP receives a malformed POST request, it generates an error condition that is improperly handled. As a result, the attacker may cause the web server to crash and possibly execute supplied code.
A vulnerability has been reported for PHP versions 4.2.0 and 4.2.1. It is possible for a remote attacker to cause the PHP interpreter to crash the web server on a vulnerable system and execute malicious, attacker supplied code.
The vulnerability is the result of the PHP interpreter incorrectly parsing MIME headers when HTTP POST commands are received. When PHP receives a malformed POST request, it generates an error condition that is improperly handled. As a result, the attacker may cause the web server to crash and possibly execute supplied code.
Exploit / POC
PHP HTTP POST Incorrect MIME Header Parsing Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PHP HTTP POST Incorrect MIME Header Parsing Vulnerability
Solution:
IBM has reported that the PHP version offered through the AIX Toolbox for Linux Applications is not vulnerable. Additionally, AIX is not vulnerable to this issue.
HP has released a security bulletin stating that HP9000 Servers running HP-UX release 11.00, 11.11, 11.20, and 11.22 with the HP Apache product installed are vulnerable to this issue. Users are advised to download the following software bundles from
http://www.software.hp.com/ISS_products_list.html:
hp apache-based web server v.1.3.26.03 on hp-ux 11.0 and 11i (pa-risc)
hp apache-based web server v.1.3.26.03 on hp-ux 11i version 1.5 and 1.6 (ipf)
hp apache-based web server v.2.0.39.03 on hp-ux 11.0 and 11i (pa-risc)
hp apache-based web server v.2.0.39.03 on hp-ux 11i (pa-risc) for ipv6
hp apache-based web server v.2.0.39.03 on hp-ux 11i version 1.5 and 1.6 (ipf)
Further details are available in HP Security Bulletin HPSBUX0208-207.
The vendor has also released a newer version of PHP to address this vulnerability:
PHP PHP 4.2 .0
PHP PHP 4.2.1
Solution:
IBM has reported that the PHP version offered through the AIX Toolbox for Linux Applications is not vulnerable. Additionally, AIX is not vulnerable to this issue.
HP has released a security bulletin stating that HP9000 Servers running HP-UX release 11.00, 11.11, 11.20, and 11.22 with the HP Apache product installed are vulnerable to this issue. Users are advised to download the following software bundles from
http://www.software.hp.com/ISS_products_list.html:
hp apache-based web server v.1.3.26.03 on hp-ux 11.0 and 11i (pa-risc)
hp apache-based web server v.1.3.26.03 on hp-ux 11i version 1.5 and 1.6 (ipf)
hp apache-based web server v.2.0.39.03 on hp-ux 11.0 and 11i (pa-risc)
hp apache-based web server v.2.0.39.03 on hp-ux 11i (pa-risc) for ipv6
hp apache-based web server v.2.0.39.03 on hp-ux 11i version 1.5 and 1.6 (ipf)
Further details are available in HP Security Bulletin HPSBUX0208-207.
The vendor has also released a newer version of PHP to address this vulnerability:
PHP PHP 4.2 .0
-
PHP php-4.2.2-Win32.zip
PHP 4.2.2 Win32 binaries.
http://www.php.net/do_download.php?download_file=php-4.2.2-Win32.zip -
PHP php-4.2.2.tar.gz
PHP 4.2.2 source code.
http://www.php.net/do_download.php?download_file=php-4.2.2.tar.gz
PHP PHP 4.2.1
-
PHP php-4.2.2-Win32.zip
PHP 4.2.2 Win32 binaries.
http://www.php.net/do_download.php?download_file=php-4.2.2-Win32.zip -
PHP php-4.2.2.tar.gz
PHP 4.2.2 source code.
http://www.php.net/do_download.php?download_file=php-4.2.2.tar.gz -
Slackware php-4.2.2-i386-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/patches/packag es/php-4.2.2-i386-1.tgz
References
PHP HTTP POST Incorrect MIME Header Parsing Vulnerability
References:
References:
- PHP Homepage (PHP Group)
- PHP Security Advisory: Vulnerability in PHP versions 4.2.0 and 4.2.1 (PHP)
- Advisory 02/2002: PHP remote vulnerability (e-matters Security
)