PHP 4.0 Bug #6642: Userspace exploit crashes web-serving machine
| From: | macabre at fl dot rr dot com | Date: | Sat, 09 Sep 2000 19:01:25 +0000 |
| Subject: | PHP 4.0 Bug #6642: Userspace exploit crashes web-serving machine | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-32774@lists.php.net to get a copy of this message | ||
From: macabre@fl.rr.com
Operating system: Debian/Linux kernel 2.2.17
PHP version: 4.0.2
PHP Bug Type: Reproduceable crash
Bug description: Userspace exploit crashes web-serving machine
Using: Apache 1.3.12/PHP4 with MySQL support
I have recently discovered a bug in PHP 4 (but not specifically 4)
which unviels the fact that any user on the system can crash the machine
with a very simple PHP document. They can do this by using the Include()
function to include the same document being loaded, causing a serious recursion problem which will
quickly max out CPU and memory usage of the web-serving machine, especially if a phpInfo() call is
done before the Include()
I am currently working on a patch for this.
Here is the exploitable code:
index.php:
<html lang="en">
<body>
<?php phpInfo(); ?>
<?php Include("./index.php"); ?>
</body>
</html>