note 116613 deleted from function.gethostbyname by salathe

From: Date: Fri, 06 Feb 2015 13:23:26 +0000
Subject: note 116613 deleted from function.gethostbyname by salathe
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-201635@lists.php.net to get a copy of this message
Note Submitter: Sijmen Ruwhof ---- On January 27, 2015 a critical security vulnerability (remote code execution possible in certain circumstances) was found in glibc's 'gethostbyname' function. This vulnerability was coined GHOST. This can also affect Linux servers running PHP that haven't been patched. Quick test to see if your server is vulnerable for a GHOST attack: php -r '$e="0";for($i=0;$i<2500;$i++)$e="0$e"; gethostbyname($e);' If you get 'Segmentation fault', then your server is vulnerable. For more information visit https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerability

« previous php.notes (#201635) next »