[security] allow_url_fopen

From: Date: Wed, 08 Aug 2001 15:11:58 +0000
Subject: [security] allow_url_fopen
Groups: php.dev 
Request: Send a blank email to php-dev+get-62567@lists.php.net to get a copy of this message
Hello, a vulnerability was published yesterday concerning a possible security hole for sites using PHP. http://www.net-security.org/text/bugs/995534301,88119,.shtml SUMMARY A local user can write a one-line script calling itself via HTTP by using fopen(). This can lead to a denial of service by exhaustion of available ports. This overrides the maximum_execution_time. SOLUTIONS - Switch allow_url_fopen to Off in php.ini DEV NOTE - This would be safe to : - include url fopen() in --disable-sockets - put allow_url_fopen Off by default in php.ini hellekin P.S.: there is another security bug affecting 4.0.5 and 4.0.6 for mail() : http://www.net-security.org/text/bugs/995534103,28541,.shtml

« previous php.dev (#62567) next »