PHP CVE-2014-5120 Multiple Arbitrary File Overwrite Vulnerabilities
BID:69375
Info
PHP CVE-2014-5120 Multiple Arbitrary File Overwrite Vulnerabilities
| Bugtraq ID: | 69375 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-5120 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2014 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | ryan |
| Vulnerable: |
Slackware Slackware Linux 14.1 Slackware Slackware Linux 14.0 Slackware Slackware Linux 13.37 Slackware Slackware Linux 13.1 Slackware Slackware Linux 13.0 PHP PHP 5.5.14 PHP PHP 5.5.13 PHP PHP 5.5.12 PHP PHP 5.5.11 PHP PHP 5.5.10 PHP PHP 5.5.5 PHP PHP 5.5.4 PHP PHP 5.5.3 PHP PHP 5.5.1 PHP PHP 5.5 PHP PHP 5.4.30 PHP PHP 5.4.29 PHP PHP 5.4.26 PHP PHP 5.4.25 PHP PHP 5.4.17 PHP PHP 5.4.14 PHP PHP 5.4.3 PHP PHP 5.4.1 PHP PHP 5.5.9 PHP PHP 5.5.8 PHP PHP 5.5.7 PHP PHP 5.5.2 PHP PHP 5.5.15 PHP PHP 5.4.31 PHP PHP 5.4.28 PHP PHP 5.4.27 PHP PHP 5.4.24 PHP PHP 5.4.23 PHP PHP 5.4.22 PHP PHP 5.4.21 PHP PHP 5.4.20 PHP PHP 5.4.19 PHP PHP 5.4.18 PHP PHP 5.4.16 PHP PHP 5.4.15 PHP PHP 5.4.13 PHP PHP 5.4.12 PHP PHP 5.4.11 PHP PHP 5.4.10 Oracle Enterprise Linux 7 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Gentoo Linux Apple Mac OS X 10.9.5 Apple Mac OS X 10.8.5 Apple Mac OS X 10.10.2 Apple Mac OS X 10.10.1 Apple Mac OS X 10.10 |
| Not Vulnerable: |
PHP PHP 5.5.16 PHP PHP 5.4.32 Apple Mac Os X 10.10.3 |
Discussion
PHP CVE-2014-5120 Multiple Arbitrary File Overwrite Vulnerabilities
PHP is prone to multiple arbitrary file-overwrite vulnerabilities because it fails to validate user-supplied input.
Successful exploits may allow an attacker to write arbitrary files in the context of the user running the affected application.
PHP versions 5.4.0 prior 5.4.32, and 5.5.0 prior 5.5.16 are vulnerable.
PHP is prone to multiple arbitrary file-overwrite vulnerabilities because it fails to validate user-supplied input.
Successful exploits may allow an attacker to write arbitrary files in the context of the user running the affected application.
PHP versions 5.4.0 prior 5.4.32, and 5.5.0 prior 5.5.16 are vulnerable.
Exploit / POC
PHP CVE-2014-5120 Multiple Arbitrary File Overwrite Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHP CVE-2014-5120 Multiple Arbitrary File Overwrite Vulnerabilities
References:
References:
- PHP 5 ChangeLog (PHP)
- PHP Homepage (PHP Group)
- CVE-2014-5120 Null byte injection possible with imagexxx functions (PHP)