PT-2014-2043 · Php+5 · Mod Php+7
Stefan Esser
·
Published
2014-07-06
·
Updated
2023-01-19
·
CVE-2014-4721
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PHP versions prior to 5.4.30
PHP versions 5.5.x prior to 5.5.14
Description
The issue is related to a "type confusion" vulnerability in the phpinfo implementation, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values for the
PHP AUTH PW, PHP AUTH TYPE, PHP AUTH USER, and PHP SELF variables. This could potentially be exploited in an Apache HTTP Server web-hosting environment with mod ssl and a PHP mod php, as demonstrated by reading a private SSL key.Recommendations
For PHP versions prior to 5.4.30, update to version 5.4.30 or later.
For PHP versions 5.5.x prior to 5.5.14, update to version 5.5.14 or later.
As a temporary workaround, consider restricting access to sensitive information in the phpinfo output until a patch is applied.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server
Centos
Php
Red Hat
Suse
Ubuntu
Mod Php
Mod Ssl