Discussions
New McAfee Vulnerability re: PHP
Info is:
Description
According to its banner, the version of PHP installed on the remote host is older than 4.4.9. Such versions may be affected by several security issues : - There are unspecified issues in the bundled PCRE library fixed by version 7.7. - A buffer overflow in the 'imageloadfont()' function in 'ext/gd/gd.c' can be triggered when a specially crafted font is given. (CVE-2008-3658) - A buffer overflow exists in the internal 'memnstr()' function, which is exposed to userspace as 'explode()'. (CVE-2008-3659) - A denial of service vulnerability exists when a filename contains 2 dots. (CVE-2008-3660) - An 'open_basedir' handling issue in