PHP emalloc() Unspecified Integer Overflow Memory Corruption Vulnerability
BID:7199
Info
PHP emalloc() Unspecified Integer Overflow Memory Corruption Vulnerability
| Bugtraq ID: | 7199 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0166 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 26 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | Discovery of this vulnerability credited to Sir Mordred <[email protected]>. |
| Vulnerable: |
PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 PHP PHP 4.0 0 |
| Not Vulnerable: | |
Discussion
PHP emalloc() Unspecified Integer Overflow Memory Corruption Vulnerability
A vulnerability has been reported in PHP version 4.3.1 and earlier. The problem occurs in the emalloc() function and may allow an attacker to corrupt memory.
The affected function reportedly fails to ensure that proper boundary checks are performed on values supplied by a malicious user. This may result in an integer overflow when emalloc() attempts to allocate memory.
Further details of this vulnerability are currently unknown. This BID will be updated as more information becomes available.
A vulnerability has been reported in PHP version 4.3.1 and earlier. The problem occurs in the emalloc() function and may allow an attacker to corrupt memory.
The affected function reportedly fails to ensure that proper boundary checks are performed on values supplied by a malicious user. This may result in an integer overflow when emalloc() attempts to allocate memory.
Further details of this vulnerability are currently unknown. This BID will be updated as more information becomes available.
Exploit / POC
PHP emalloc() Unspecified Integer Overflow Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PHP emalloc() Unspecified Integer Overflow Memory Corruption Vulnerability
Solution:
SCO has released security advisory CSSA-2003-SCO.28 with fixes and specific resolution steps. The advisory addresses this issue in OpenServer 5.0.5 through 5.0.7.
Solution:
SCO has released security advisory CSSA-2003-SCO.28 with fixes and specific resolution steps. The advisory addresses this issue in OpenServer 5.0.5 through 5.0.7.
References
PHP emalloc() Unspecified Integer Overflow Memory Corruption Vulnerability
References:
References: