PT-2014-2043 · Php+5 · Mod Php+7

Stefan Esser

·

Published

2014-07-06

·

Updated

2023-01-19

·

CVE-2014-4721

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.4.30 PHP versions 5.5.x prior to 5.5.14
Description The issue is related to a "type confusion" vulnerability in the phpinfo implementation, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values for the PHP AUTH PW, PHP AUTH TYPE, PHP AUTH USER, and PHP SELF variables. This could potentially be exploited in an Apache HTTP Server web-hosting environment with mod ssl and a PHP mod php, as demonstrated by reading a private SSL key.
Recommendations For PHP versions prior to 5.4.30, update to version 5.4.30 or later. For PHP versions 5.5.x prior to 5.5.14, update to version 5.5.14 or later. As a temporary workaround, consider restricting access to sensitive information in the phpinfo output until a patch is applied.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2022-02649
CESA-2014_1012
CESA-2014_1013
CVE-2014-4721
DLA-0018-1
DSA-2974-1
MGASA-2014-0283
MGASA-2014-0284
RHSA-2014:1012
RHSA-2014:1013
RHSA-2014:1765
RHSA-2014:1766
RHSA-2014_1012
RHSA-2014_1013
SUSE-SU-2016:1638-1
USN-2276-1

Affected Products

Apache Http Server
Centos
Php
Red Hat
Suse
Ubuntu
Mod Php
Mod Ssl