[Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability]
| From: | Stefan Neufeind, PEAR | Date: | Wed, 25 Oct 2006 17:48:04 +0000 |
| Subject: | [Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability] | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-44747@lists.php.net to get a copy of this message | ||
Hi PEARs,
though as usual this information is not throughly checked by Secunia,
there is some truth behind it. The version-number they wanted to point
out is 0.03 and not 0.3, though even a newer version exists. But anyway :-)
The vuln they point to actually and still exists. Bug
http://pear.php.net/bugs/bug.php?id=9162 was
opened for this.
Are there any objections to replace $phpdns_basedir with "Net_"
completely in the package? (Though this is actually a BC-break!!)
Regards,
Stefan
-------- Original Message --------
Subject: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability
Date: 25 Oct 2006 13:32:14 -0000
From: Secunia Security Advisories <sec-adv@secunia.com>
TITLE:
Net_DNS "phpdns_basedir" File Inclusion Vulnerability
SECUNIA ADVISORY ID:
SA22522
VERIFY ADVISORY:
http://secunia.com/advisories/22522/
CRITICAL:
Highly critical
IMPACT:
System access
WHERE:
From remote
SOFTWARE:
Net_DNS 0.x
http://secunia.com/product/12419/
DESCRIPTION:
Drago84 has discovered a vulnerability in Net_DNS, which can be
exploited by malicious people to compromise a vulnerable system.
Input passed to the "phpdns_basedir" parameter in DNS/RR.php is not
properly verified before being used to include files. This can be
exploited to include arbitrary files from local or external
resources.
Successful exploitation requires that "register_globals" is enabled.
The vulnerability is confirmed in version 0.3. Other versions may
also be affected.
SOLUTION:
Edit the source code to ensure that input is properly verified.
PROVIDED AND/OR DISCOVERED BY:
Drago84
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/