From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-200402-01.xml | 72 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 72 insertions(+) create mode 100644 metadata/glsa/glsa-200402-01.xml (limited to 'metadata/glsa/glsa-200402-01.xml') diff --git a/metadata/glsa/glsa-200402-01.xml b/metadata/glsa/glsa-200402-01.xml new file mode 100644 index 000000000000..92d65863df45 --- /dev/null +++ b/metadata/glsa/glsa-200402-01.xml @@ -0,0 +1,72 @@ + + + + PHP setting leaks from .htaccess files on virtual hosts + + If the server configuration "php.ini" file has + "register_globals = on" and a request is made to one virtual host + (which has "php_admin_flag register_globals off") and the next + request is sent to the another virtual host (which does not have the + setting) global variables may leak and may be used to exploit the + site. + + PHP + 2004-02-07 + 2004-02-07: 01 + 39952 + remote + + + 4.3.4-r4 + 4.3.4-r4 + + + +

+ PHP is a widely-used general-purpose scripting language that is + especially suited for Web development and can be embedded into HTML. +

+
+ +

+ If the server configuration "php.ini" file has + "register_globals = on" and a request is made to one virtual host + (which has "php_admin_flag register_globals off") and the next + request is sent to the another virtual host (which does not have the + setting) through the same apache child, the setting will persist. +

+
+ +

+ Depending on the server and site, an attacker may be able to exploit + global variables to gain access to reserved areas, such as MySQL passwords, + or this vulnerability may simply cause a lack of functionality. As a + result, users are urged to upgrade their PHP installations. +

+

+ Gentoo ships PHP with "register_globals" set to "off" + by default. +

+

+ This issue affects both servers running Apache 1.x and servers running + Apache 2.x. +

+
+ +

+ No immediate workaround is available; a software upgrade is required. +

+
+ +

+ All users are recommended to upgrade their PHP installation to 4.3.4-r4: +

+ + # emerge sync + # emerge -pv ">=dev-php/mod_php-4.3.4-r4" + # emerge ">=dev-php/mod_php-4.3.4-r4" +
+ + Corresponding PHP bug + +
-- cgit v1.2.3