php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Sec Bug #55693 Vulnerability Issues
Submitted: 2011-09-14 13:28 UTC Modified: 2013-02-18 00:35 UTC
Votes:2
Avg. Score:2.0 ± 1.0
Reproduced:2 of 2 (100.0%)
Same Version:0 (0.0%)
Same OS:0 (0.0%)
From: m dot achappan at gmail dot com Assigned:
Status: No Feedback Package: *General Issues
PHP Version: 5.3.8 OS: Redhat Linux 5.5
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: m dot achappan at gmail dot com
New email:
PHP Version: OS:

 

 [2011-09-14 13:28 UTC] m dot achappan at gmail dot com
Description:
------------
Hi Sir,

   I need some solution related to vulnerability issues. Recently I did the upgrade from php version 5.2.1 to 5.3.8 because of below vulnerabilities. After upgrading, its still showing same vulnerabilities and not fixed. Please provide me your solution and suggestion to fix it.

1. Secure Socket Layer (SSL) Expired Certificate
2. PHP php_sprintf_appendstring() Remote Integer Overflow Vulnerability
3. PHP expose_php Information Disclosure Vulnerability
4. PHP Multiple Iconv Functions Denial Of Service Vulnerability
5. PHP iconv_substr() Denial Of Service Vulnerability
6. PHP .htaccess safe_mode And open_basedir Security Bypass Vulnerability
7. PHP sqlite_udf_decode_binary() Buffer Overflow Vulnerability
8. PHP sqlite_udf_decode_binary() Buffer Overflow Vulnerability
9. PHP imap_mail_compose() Stack Buffer Overflow Vulnerability
10. PHP php_stream_filter_create() Buffer Overflow Vulnerability
11. PHP ext/filter FDF Support Post Bypass Vulnerability
12. PHP substr_compare() Integer Overflow Vulnerability


Thanks and Regards,
Achappan Mahalingam


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-11-14 18:39 UTC] felipe@php.net
-Summary: Vulnerability Issues: +Summary: Vulnerability Issues
 [2011-11-14 18:39 UTC] felipe@php.net
Where are you seeing those vulns list?
I can't reproduce the vulns which you have listed, and I can see them listed along the changelog.
 [2011-11-16 11:00 UTC] m dot achappan at gmail dot com
Hi Thanks,

   In our organization system people using some scanning tool for vulnerablilities. After completion of scanning, they will send a reports to developer to solve the issues. Previous vulnerabilities has been solved because of upgraded into new php version 5.3.8 but getting some other new vulnerabilities. Can you please tell me how to solve this issue?
   1. (3554) Secure Socket Layer (SSL) Expired Certificate
   2. (12690) (2588513) TLS-SSL Server Blockwise Chosen-Boundary Browser Weakness
 [2011-11-22 21:15 UTC] stas@php.net
-Status: Open +Status: Feedback
 [2011-11-22 21:15 UTC] stas@php.net
The proper way to do it would be to submit bug reports for the problems you are 
having including:

1. Detailed description of the problem
2. Example code reproducing the problem
3. The result that you expect this code to produce
4. The result that the code produces instead
5. PHP version and OS you are running
 [2013-02-18 00:35 UTC] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Open". Thank you.
 
PHP Copyright © 2001-2024 The PHP Group
All rights reserved.
Last updated: Sat Dec 21 16:01:28 2024 UTC