OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[VulnDiscuss] Re: [Full-Disclosure] Advisory 11/2004: PHP memory_limit remote vulnerability

From: Florian Weimer (fwdeneb.enyo.de)
Date: Wed Jul 14 2004 - 02:55:45 CDT


* Stefan Esser:

> Application: PHP <= 4.3.7
> PHP5 <= 5.0.0RC3
> Severity: A vulnerability within PHP allows remote code
> execution on PHP servers with activated memory_limit
> Risk: Critical

Uh-oh. Has anybody got a minimal patch to fix this issue (and only
this issue)?