PT-2007-2805 · Microsoft+1 · Ntwdblib.Dll+1
Rgod
·
Publicado
2007-03-10
·
Atualizado
2018-10-19
·
CVE-2007-1411
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHP versions prior to 4.4.7
PHP 5 versions (affected versions not specified)
Description
The issue is caused by a buffer overflow that allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the
mssql connect and mssql pconnect functions. This is due to a boundary error when processing arguments within the dbopen() function in NTWDBLIB.DLL. The vulnerability can be exploited by passing an overly long string (greater than 260 bytes) as an argument to the mssql connect() or mssql pconnect() functions, allowing attackers to bypass security restrictions like the disable functions directive.Recommendations
For PHP versions prior to 4.4.7, consider upgrading to a newer version to mitigate the risk.
For PHP 5 versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to the
mssql connect() and mssql pconnect() functions until a patch is available.Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ntwdblib.Dll
Php