Get a Pentest and security assessment of your IT network.

Advisories

Mandriva Linux Security Advisory 2007.038

Mandriva Linux Security Advisory – PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a “;” in a session_save_path argument, followed by an allowed path, which causes a parsing inconsistency in which PHP validates the allowed path but sets session.save_path to the malicious path. Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font. PHP uses an embedded copy of GD and may be susceptible to the same issue.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54257/MDKSA-2007-038.txt

Source: https://packetstormsecurity.com/files/54257/Mandriva-Linux-Security-Advisory-2007.038.html

Related posts
Advisories

Secunia Security Advisory 19451

Advisories

Debian Linux Security Advisory 1187-1

Advisories

Secunia Security Advisory 25148

Advisories

Secunia Security Advisory 28461