Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP memory_limit Remote Code Execution Vulnerability

PHP modules compiled with memory_limit support are affected by a remote code-execution vulnerability. This issue occurs because the PHP module fails to properly handle memory_limit request termination.

An attacker can leverage this issue by exploiting the Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability (BID 10619). The attacker can cause premature termination during critical code execution. Note that although the Apache vulnerability is the only known attack vector, there may be other attack vectors that are currently unknown.

Attackers can exploit this issue to execute arbitrary code on an affected computer within the context of the vulnerable application, facilitating unauthorized access.







 

Privacy Statement
Copyright 2009, SecurityFocus