store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed Jun 19, 2013 7:46 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 
Author Message
 Post subject: Suhosin
Unread postPosted: Tue Feb 07, 2012 5:28 pm 
Offline
Forum User
Forum User

Joined: Sat Sep 25, 2010 2:46 pm
Posts: 97
FYI:

__

PHP Suhosin Extension Transparent Cookie Encryption Buffer Overflow Vulnerability

Description

A vulnerability has been reported in the Suhosin extension for PHP, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to a boundary error within the transparent cookie encryption. If cookie encryption is enabled (disabled by default), this can be exploited to cause a stack-based buffer overflow by e.g. sending specially crafted input to an affected script.

Successful exploitation may allow execution of arbitrary code, but e.g. requires an application to pass untrusted input to the "header()" function when setting a cookie and a weak Suhosin configuration (e.g. multiheader option enabled and NULL-byte protection disabled, both not default).

The vulnerability is reported in versions prior to 0.9.33.

Solution
Update to version 0.9.33.

__


Top
 Profile  
 
 Post subject: Re: Suhosin
Unread postPosted: Wed Feb 08, 2012 9:10 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7460
Location: earth
This does not effect you if you are using an ASL kernel (any version) by way of the PaX security policy.


Top
 Profile  
 
 Post subject: Re: Suhosin
Unread postPosted: Wed Feb 08, 2012 11:08 am 
Offline
Forum User
Forum User

Joined: Sat Sep 25, 2010 2:46 pm
Posts: 97
Scott:

Thanks. Figured it wasn't an issue in ASL but figured the Atomic suhosin rpm would need an update for non-ASL systems using said package.


Top
 Profile  
 
 Post subject: Re: Suhosin
Unread postPosted: Wed Feb 08, 2012 11:57 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3265
Location: Chantilly, VA
Quote:
Thanks. Figured it wasn't an issue in ASL but figured the Atomic suhosin rpm would need an update for non-ASL systems using said package.


All the more reason to run ASL, you never have to worry about things like this. ;-)

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Suhosin
Unread postPosted: Wed Feb 08, 2012 12:08 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7460
Location: earth
And the update, 0.9.33 is going to the mirrors now.

As always thanks for the report, security advisories are very welcome!


Top
 Profile  
 
 Post subject: Re: Suhosin
Unread postPosted: Wed Feb 08, 2012 6:25 pm 
Offline
Forum User
Forum User

Joined: Sat Sep 25, 2010 2:46 pm
Posts: 97
Great, thanks.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group