PHP socket_iovec_alloc() integer overflow

PHP socket_iovec_alloc() integer overflow

Published on 2004-03-27. Updated on 2007-03-20.

Description:

This alert was generated using only banner information. It may be a false positive.

Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes.

Affected PHP versions (up to 4.3.1).

Impact:
Allow remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.

Recommendation:
Upgrade PHP to the latest version.

Tags: Scripts

Alert Tags: configuration
ApplicableApplicationServer : PHP
ApplicableOS: All
ApplicableWebServer: All

References:

  • CVE 2003-0172
  • PHP Homepage

  • Go Back