Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  NEWS  community  lists  Wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Wed, 13 Aug 2008 12:53:04 +0200
From: Christian Hoffmann <hoffie@...too.org>
To: oss-security@...ts.openwall.com
CC: coley@...re.org
Subject: Re: CVE request: php-5.2.6 overflow issues

On 2008-08-13 02:45, Steven M. Christey wrote:
> On Fri, 8 Aug 2008, Christian Hoffmann wrote:
> 
>> two security issues, which might possibly allow for arbitrary code
>> execution (afaik nobody has analyzed the details...), but at least DoS
>> (think of FastCGI setups), were silently fixed in PHP again:
>>
>>    * Overflow in ext/gd's imageloadfont() function [1] [2] [3]
> 
> Use CVE-2008-3658, to be filled in later - I'm assuming this is a distinct
> component that doesn't just affect PHP.
Pierre from php and libgd upstream just confirmed that the vulnerable 
code is only present in php's copy (fork) of libgd. The independent 
libgd library is not vulnerable to this problem.

-- 
Christian Hoffmann


[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ