There have been a number of reports circulating about possible
vulnerabilities in PHP=2E I'm going to address them one-by-one:
* Integer Overflow in socket_iovec_alloc()
WRONG! This is a Null-pointer de-reference:
EAX =3D 00000000
EDI =3D 41414141
0085353A 8B 38 mov edi,dword ptr [eax]
The access violation occurs in a read error=2E This is not exploitable to=
gain control of the PHP interpreter, nor is it an integer overflow of any
kind=2E It is simply a null-read, and the lone register controlled by use=
r
data is obliterated by that instruction if the call succeeds=2E
* Buffer overflow in openlog()
I've tried passing long parameters (and large integers) to openlog()=2E N=
o
crashes could be caused by this "exploit"=2E I was unable to demonstrate =
any
disruption to PHP via this "vulnerability", let alone complete control=2E=20=
Unless the vendor or the original reporter will confirm this with code
(which was, oddly enough, MISSING from the original advisory), I don't
believe this "flaw" (if it exists) can do any damage to a default
production system=2E
* Integer overflow in emalloc()
Funny -- there is not an emalloc() function (nor malloc, calloc, etc=2E)
because ALL memory allocation is handled by the interpreter itself=2E=20
Therefore, this report is completely bogus=2E
--------------------------------------------------------------------
mail2web - Check your email from the web at
http://mail2web=2Ecom/ =2E

Likes:

Quote