News Feed
Jobs Feed
Sections

Recent Jobs

News Archive
Hardened-PHP Project:
PHP HTML Entity Encoder Heap Overflow Vulnerability
November 03, 2006 @ 12:58:00

The Hardened-PHP Project has put out another advisory for the PHP distribution itself, versions 5.1.6/4.4.4 and below dealing with the HTML entity encoder heap.

While we were searching for a hole in htmlspecialchars() and htmlentities() to bypass the encoding of certain chars to exploit a possible eval() injection hole in another application we discovered that the implementation contains a possible bufferoverflow that can be triggered when the UTF-8 charset is selected.

The issue has been corrected in the latest PHP 5 release - version 5.2 - but is still present in the PHP 4.4 series (they have a recommended patch until the new version is posted). You can get complete information about this issue from the full vulnerability listing.

0 comments voice your opinion now!
html entity encoded heap overflow vulnerability download update html entity encoded heap overflow vulnerability download update



Similar Posts

Stefan Esser's Blog: MOPB: First Reactions

Debuggable Blog: Better array syntax for PHP: Here's your chance to weigh in

Milw0rm.com: Exploit - PHP5 COM Object Security Bypass (Windows)

Community News: Joomla! Major Security Update - v1.0.10

PHPImpact Blog: PHP Simple HTML DOM Parser (jQuery Style)


Community Events







Don't see your event here?
Let us know!


PHP5 mysql PEAR developer releases zend zendframework release job ajax database code package conference security book cakephp application example framework

All content copyright, 2008 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework