Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 26782 - dev-php/phpsysinfo
Summary: dev-php/phpsysinfo
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Highest critical (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-08-17 01:02 UTC by Daniel Ahlberg (RETIRED)
Modified: 2011-10-30 22:40 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Patch to disallow '..' in template and language filenames (phpsysinfo-2.1-urlencoded-security-fix.diff,503 bytes, patch)
2003-10-12 12:39 UTC, Doug Weimer
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Ahlberg (RETIRED) gentoo-dev 2003-08-17 01:02:29 UTC
-------------------------------------------------------------------------- 
Debian Security Advisory DSA 346-1                     security@debian.org 
http://www.debian.org/security/                             Matt Zimmerman 
July 8th, 2003                          http://www.debian.org/security/faq 
-------------------------------------------------------------------------- 
 
Package        : phpsysinfo 
Vulnerability  : directory traversal 
Problem-Type   : local 
Debian-specific: no 
CVE Ids        : CAN-2003-0536 
 
Albert Puigsech Galicia <ripe@7a69ezine.org> reported that phpsysinfo, 
a web-based program to display status information about the system, 
contains two vulnerabilities which could allow local files to be read, 
or arbitrary PHP code to be executed, under the privileges of the web 
server process (usually www-data).  These vulnerabilities require 
access to a writable directory on the system in order to be exploited.
Comment 1 Doug Weimer 2003-10-12 12:39:41 UTC
Created attachment 19141 [details, diff]
Patch to disallow '..' in template and language filenames

This patch is an excerpt from the patch collection provided by Frederik
Schueler here: http://users.idf.de/~fs/debian/phpsysinfo_2.1-1.diff.gz .
The
"debian/" additions and kernel 2.{5,6} memory display fix were removed from
the
referenced patch as the do not address this particular bug.
Comment 2 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2003-10-13 19:53:46 UTC
CVS updated to -r1 with patch from offical debian source.
Comment 3 Martin Holzer (RETIRED) gentoo-dev 2003-11-02 10:53:03 UTC
closing