Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Ubuntu Local Security Checks --> Category: infos

USN112-1 : php4 vulnerabilities Vulnerability Scan


Vulnerability Scan Summary
php4 vulnerabilities

Detailed Explanation for this Vulnerability Test

Synopsis :

These remote packages are missing security patches :
- libapache2-mod-php4
- php4
- php4-cgi
- php4-curl
- php4-dev
- php4-domxml
- php4-gd
- php4-ldap
- php4-mcal
- php4-mhash
- php4-mysql
- php4-odbc
- php4-pear
- php4-recode
- php4-snmp
- php4-sybase
- php4-xslt


Description :

An integer overflow was discovered in the exif_process_IFD_TAG()
function in PHP4's EXIF module. EXIF tags with a specially crafted
"Image File Directory" (IFD) tag caused a buffer overflow which could
have been exploited to execute arbitrary code with the rights of
the PHP4 server. (CVE-2005-1042)

The same module also contained a Denial of Service vulnerability. EXIF
headers with a large IFD nesting level caused an unbound recursion
which would eventually overflow the stack and cause the executed
program to crash. (CVE-2005-1043)

In web applications that automatically process EXIF tags of uploaded
images, both vulnerabilities could be exploited remotely.

Solution :

Upgrade to :
- libapache2-mod-php4-4.3.8-3ubuntu7.8 (Ubuntu 4.10)
- php4-4.3.8-3ubuntu7.8 (Ubuntu 4.10)
- php4-cgi-4.3.8-3ubuntu7.8 (Ubuntu 4.10)
- php4-curl-4.3.8-3ubuntu7.8 (Ubuntu 4.10)
- php4-dev-4.3.8-3ubuntu7.8 (Ubuntu 4.10)
- php4-domxml-4.3.8-3ubuntu7.8 (Ubuntu 4.10)
- php4-gd-4.3.8-3ubuntu7.8 (Ubuntu 4.10)
- php4-ldap-4.3.8-3ubuntu7.8 (Ubuntu 4.10)
- php4-mcal-4.3.8-3ubuntu7.8 (Ubuntu 4.10)
- php4-mhash-4.3.8-3ubuntu7.8 (Ubuntu 4.10)
- php4-mysql-4.3.8-3ubuntu7.8 (Ubuntu 4.10)
- php4-odbc-4.3.8-3
[...]


Threat Level: High


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.