note 116613 added to function.gethostbyname

From: Date: Thu, 29 Jan 2015 13:30:41 +0000
Subject: note 116613 added to function.gethostbyname
Groups: php.notes 
Request: Send a blank email to php-notes+get-201552@lists.php.net to get a copy of this message
On January 27, 2015 a critical security vulnerability (remote code execution possible in certain circumstances) was found in glibc's 'gethostbyname' function. This vulnerability was coined GHOST. This can also affect Linux servers running PHP that haven't been patched. Quick test to see if your server is vulnerable for a GHOST attack: php -r '$e="0";for($i=0;$i<2500;$i++)$e="0$e"; gethostbyname($e);' If you get 'Segmentation fault', then your server is vulnerable. For more information visit https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerability ---- Server IP: 72.52.91.14 Probable Submitter: 62.41.23.0 ---- Manual Page -- http://php.net/manual/en/function.gethostbyname.php Edit -- https://master.php.net/note/edit/116613 Del: integrated -- https://master.php.net/note/delete/116613/integrated Del: useless -- https://master.php.net/note/delete/116613/useless Del: bad code -- https://master.php.net/note/delete/116613/bad+code Del: spam -- https://master.php.net/note/delete/116613/spam Del: non-english -- https://master.php.net/note/delete/116613/non-english Del: in docs -- https://master.php.net/note/delete/116613/in+docs Del: other reasons-- https://master.php.net/note/delete/116613 Reject -- https://master.php.net/note/reject/116613 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#201552) next »