[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2012-095 --- php

ID: oval:org.secpod.oval:def:1601283Date: (C)2020-11-27   (M)2024-03-20
Class: PATCHFamily: unix




Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow. The crypt_des function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

Platform:
Amazon Linux AMI
Product:
php
Reference:
ALAS-2012-95
CVE-2012-2143
CVE-2012-2386
CVE    2
CVE-2012-2143
CVE-2012-2386
CPE    120
cpe:/a:php:php:3.0
cpe:/a:php:php:5.0.0:rc3
cpe:/a:php:php:5.0.0:rc2
cpe:/a:php:php:5.0.0:rc1
...

© SecPod Technologies