Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200804-19 ] PHP Toolkit: Data disclosure and Denial of Service
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Advocate
Advocate


Joined: 12 May 2004
Posts: 2663

PostPosted: Fri Apr 18, 2008 12:26 am    Post subject: [ GLSA 200804-19 ] PHP Toolkit: Data disclosure and Denial o Reply with quote

Gentoo Linux Security Advisory

Title: PHP Toolkit: Data disclosure and Denial of Service (GLSA 200804-19)
Severity: normal
Exploitable: local
Date: April 17, 2008
Bug(s): #209535
ID: 200804-19

Synopsis

PHP Toolkit does not quote parameters, allowing for PHP source code disclosure on Apache, and a Denial of Service.

Background

PHP Toolkit is a utility to manage parallel installations of PHP within Gentoo. It is executed by the PHP ebuilds at setup.

Affected Packages

Package: app-admin/php-toolkit
Vulnerable: < 1.0.1
Unaffected: >= 1.0.1
Architectures: All supported architectures


Description

Toni Arnold, David Sveningsson, Michal Bartoszkiewicz, and Joseph reported that php-select does not quote parameters passed to the "tr" command, which could convert the "-D PHP5" argument in the "APACHE2_OPTS" setting in the file /etc/conf.d/apache2 to lower case.

Impact

An attacker could entice a system administrator to run " emerge php " or call " php-select -t apache2 php5 " directly in a directory containing a lower case single-character named file, which would prevent Apache from loading mod_php and thereby disclose PHP source code and cause a Denial of Service.

Workaround

Do not run "emerge" or "php-select" from a working directory which contains a lower case single-character named file.

Resolution

All PHP Toolkit users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-admin/php-toolkit-1.0.1"


References

CVE-2008-1734
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum