, The Register 2002-07-23
The PHP form-data POST handler is susceptible to a malicious POST request that can trigger an error condition which, depending on your hardware, can crash the machine or provide for remote exploitation.
PHP versions 4.2.0 and 4.2.1 are vulnerable. The PHP Group has released both a fixed version and patches, including binaries for Windows, available for download here.
If immediate tinkering proves inconvenient, the team recommends a temporary workaround of denying POST requests on any affected servers.
The issue was discovered by Stefan Esser of eMatters Security. ®
