Re: cvs: php4(PHP_4_0_7) /main rfc1867.c
| From: | Rasmus Lerdorf | Date: | Thu, 28 Feb 2002 09:19:21 +0000 |
| Subject: | Re: cvs: php4(PHP_4_0_7) /main rfc1867.c | ||
| References: | 1 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-9499@lists.php.net to get a copy of this message | ||
Well, I would guess that the current exploits can not be used against
4.1.2, so in that sense it is still useful. But yes, this memchr()+1
screwup could potentially be used to create another weird exploit by
sending a very specific mangled file upload header. I can't quite picture
what it would look like, and I am not completely sure it is possible.
This thing needs more eyes...
-Rasmus
On Thu, 28 Feb 2002, Edin Kadribasic wrote:
> > > Does this mean 4.1.2 is broken?
> > Yes
>
> How badly broken is it? Does this also apply to "File Uploads Security Fix"
> that can be downloaded from from php.net?
>
> Edin
>