PHP < 4.4.3 / 5.1.4 Multiple Vulnerabilities

high Nessus Plugin ID 22268

Synopsis

The remote web server uses a version of PHP that is affected by multiple flaws.

Description

According to its banner, the version of PHP installed on the remote host is older than 4.4.3 / 5.1.4. Such versions may be affected by several issues, including a buffer overflow, heap corruption, and a flaw by which a variable may survive a call to 'unset()'.

Solution

Upgrade to PHP version 4.4.3 / 5.1.4 or later.

See Also

http://www.nessus.org/u?a7553cd8

http://www.nessus.org/u?ccaf872d

https://www.securityfocus.com/archive/1/archive/1/442437/100/0/threaded

http://us3.php.net/releases/4_4_3.php

http://us3.php.net/releases/5_1_3.php

http://www.php.net/release_5_1_4.php

Plugin Details

Severity: High

ID: 22268

File Name: php_4_4_3.nasl

Version: 1.27

Type: remote

Family: CGI abuses

Published: 8/25/2006

Updated: 5/31/2024

Configuration: Enable thorough checks

Supported Sensors: Nessus

Enable CGI Scanning: true

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:php:php

Required KB Items: www/PHP

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No exploit is required

Patch Publication Date: 8/3/2006

Vulnerability Publication Date: 3/28/2006

Reference Information

CVE: CVE-2006-0996, CVE-2006-1490, CVE-2006-1494, CVE-2006-1608, CVE-2006-1990, CVE-2006-1991, CVE-2006-2563, CVE-2006-2660, CVE-2006-3011, CVE-2006-3016, CVE-2006-3017, CVE-2006-3018, CVE-2006-4433

BID: 17296, 17362, 17439, 17843, 18116, 18645, 49634

CWE: 79