News Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Hardened-PHP Project:
Advisory - PHP unserialize() Array Creation Integer Overflow
October 09, 2006 @ 13:41:22

The Hardened-PHP project has just released another advisory about core PHP functionality, specifically in the unserialize function when dealing with arrays.

The PHP 5 branch of the PHP source code lacks the protection against possible integer overflows inside ecalloc() that is present in the PHP 4 branch and also for several years part of our Hardening-Patch and our new Suhosin-Patch.

It was discovered that such an integer overflow can be triggered when user input is passed to the unserialize() function.

You can get the full details from this advisory release including a recommendation to patch the installation until it is corrected in the current distribution.

0 comments voice your opinion now!
advisory unserialize core array creation integer overflow advisory unserialize core array creation integer overflow


blog comments powered by Disqus

Similar Posts

PHPClasses.org: Lately in PHP, Episode 22 - Will the Git Move Encourage more Non-Core Contribution?

Ben Scholzen's Blog: Writing powerful and easy config files with PHP-arrays

Freek Lijten's Blog: Currently on PHP's internals...

Secunia.com: Fedora update for PHP

Christopher Kunz\'s Blog: Hardened-PHP Advisory 22/2005 - phpSysInfo


Community Events

Don't see your event here?
Let us know!


series voicesoftheelephpant laravel5 library release opinion extension framework video psr7 interview laravel language podcast development api introduction community conference unittest

All content copyright, 2015 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework