[security] allow_url_fopen
| From: | Hellekin O. Wolf | Date: | Wed, 08 Aug 2001 15:11:58 +0000 |
| Subject: | [security] allow_url_fopen | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-62567@lists.php.net to get a copy of this message | ||
Hello,
a vulnerability was published yesterday concerning a possible security hole for sites using PHP.
http://www.net-security.org/text/bugs/995534301,88119,.shtml
SUMMARY
A local user can write a one-line script calling itself via HTTP by using fopen().
This can lead to a denial of service by exhaustion of available ports.
This overrides the maximum_execution_time.
SOLUTIONS
- Switch allow_url_fopen to Off in php.ini
DEV NOTE
- This would be safe to :
- include url fopen() in --disable-sockets
- put allow_url_fopen Off by default in php.ini
hellekin
P.S.: there is another security bug affecting 4.0.5 and 4.0.6 for mail() : http://www.net-security.org/text/bugs/995534103,28541,.shtml