CNCVE编号:CNCVE-20020018 CVE编号:CAN-2002-0081 安全级别:高 漏洞中文描述: BUGTRAQ ID: 4183PHP是一种被广泛使用的脚本语言,用于基于Web的CGI程序,它可被安装在包括Apache、IIS、 Caudium、Netscape、iPlanet和OmniHTTPd等多种web服务器上。PHP 4.1.2以前的实现中存在缓冲区溢出漏洞,远程攻击者可以通过溢出攻击在主机上执行任意指令。PHP支持multipart/form-data POST请求(RFC1868),实现了POST文件上传。但是用于解码MIME数据的php_mime_split函数存在缓冲区溢出问题,远程攻击者可以利用这个漏洞在主机上以Web服务器进程的身份执行任意指令。不仅PHP4受这个漏洞影响,而且以前的PHP3也受此漏洞的影响,Apache的PHP模块也存在这个漏洞。使用cvs PHP 4.2.0-dev版本的用户不受上述安全漏洞的影响,因为4.2.0系列的文件上传代码已完全重写。 漏洞英文描述: PHP is a widely deployed scripting language, designed for web based development and CGI programming. PHP does not perform proper bounds checking on in functions related to Form-based File Uploads in HTML (RFC1867). Specifically, this problem occurs in the functions which are used to decode MIME encoded files. As a result, it may be possible to overrun the buffer used for the vulnerable functions to cause arbitrary attacker-supplied instructions to be executed. PHP is invoked through webservers remotely. It may be possible for remote attackers to execute this vulnerability to gain access to target systems. A vulnerable PHP interpreter module is available for Apache servers that is often enabled by default. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0314.html http://www.debian.org/security/2002/dsa-115 http://www.linuxsecurity.com/advisories/other_advisory-1924.html https://www.redhat.com/support/errata/RHSA-2002-035.html http://www.cert.org/ 系统类型: Win2000/NT 漏洞类型:缓冲区溢出