[Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability]

From: Date: Wed, 25 Oct 2006 17:48:04 +0000
Subject: [Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability]
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-44747@lists.php.net to get a copy of this message
Hi PEARs, though as usual this information is not throughly checked by Secunia, there is some truth behind it. The version-number they wanted to point out is 0.03 and not 0.3, though even a newer version exists. But anyway :-) The vuln they point to actually and still exists. Bug http://pear.php.net/bugs/bug.php?id=9162 was opened for this. Are there any objections to replace $phpdns_basedir with "Net_" completely in the package? (Though this is actually a BC-break!!) Regards, Stefan -------- Original Message -------- Subject: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability Date: 25 Oct 2006 13:32:14 -0000 From: Secunia Security Advisories <sec-adv@secunia.com> TITLE: Net_DNS "phpdns_basedir" File Inclusion Vulnerability SECUNIA ADVISORY ID: SA22522 VERIFY ADVISORY: http://secunia.com/advisories/22522/ CRITICAL: Highly critical IMPACT: System access WHERE: From remote SOFTWARE: Net_DNS 0.x http://secunia.com/product/12419/ DESCRIPTION: Drago84 has discovered a vulnerability in Net_DNS, which can be exploited by malicious people to compromise a vulnerable system. Input passed to the "phpdns_basedir" parameter in DNS/RR.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources. Successful exploitation requires that "register_globals" is enabled. The vulnerability is confirmed in version 0.3. Other versions may also be affected. SOLUTION: Edit the source code to ensure that input is properly verified. PROVIDED AND/OR DISCOVERED BY: Drago84 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/

« previous php.pear.dev (#44747) next »