Page 1 of 1

PHP blasted with double-barrelled security holes

Posted: Sun Jul 18, 2004 12:23 pm
by Tami
PHP blasted with double-barrelled security holes
Two vulnerabilities allow for code execution on both servers and PCs.


By Matthew Broersma, [url="http://www.techworld.com"]TechWorld[/url]


PHP contains two critical bugs that could allow someone to take over a server and use a browser to run dangerous code, German IT security firm E-matters has warned.


PHP is the most popular scripting module on Apache servers and is enabled on at least half of all Apache servers, according to figures from SecuritySpace. The browsers affected are Explorer and Safari - accounting for virtually the entire market.


The PHP Group issued a [url="http://www.php.net/release_4_3_8.php"]Patch[/url] for the flaws on Wednesday, and Linux vendors have also begun releasing fixes tailored for their particular distributions, according to security firm Secunia, which maintains a vulnerabilities database.


On Wednesday, the PHP Group also released the final version of PHP 5.0, which fixes the flaws. The bugs were confirmed in PHP versions 4.3.7 and earlier, and PHP 5.0 release candidate 3 and earlier.


The first flaw, involving various errors in PHP's memory_limit request termination, could be exploited to allow an attacker to execute arbitrary code on a server with a vulnerable implementation of PHP enabled, researchers said. The exploit works on any platform, according to a report by E-matters researcher Stefan Esser, who said he discovered the problem during a re-audit of memory_limit following a related advisory late last month. Vendors were notified a week ago and the problem was made public on Wednesday, E-matters said.


The second problem could be used to launch unsafe code in Internet Explorer and Apple's Safari browser because of the way those browsers handle miscoded HTML. PHP's strip_tags() function is often used to block cross-site scripting attacks by removing unsafe HTML from user input. However, it is possible to slip unsafe script past strip_tags() by inserting characters such as \0 in the input - for example disguising a "script" tag as "\0script".


Such tags would have no effect on most browsers because they would be considered errors and ignored. However, a feature in IE and Safari strips out errors such as \0 and then renders the code, thus allowing potentially dangerous code to render in the browser. The server patch blocks the dangerous code from reaching the browsers.


Cross-site scripting attacks can run malicious tags and code in a browser as a result of clicking on a hyperlink or reading an email. Such attacks can result in hijacking a user session, changing user settings, stealing browser cookies and other exploits, according to security advisory service CERT.


Secunia researchers said IE and Safari had been rendered vulnerable by a feature whose security implications hadn't been considered clearly enough. "This is not a vulnerability in those browsers, but unfortunate and unnecessary functionality," the firm said in its advisory.


[url="http://security.e-matters.de/advisories/112004.html"]Advisory On Problem One[/url]

Advisory 11/2004
PHP memory_limit remote vulnerability

Release Date: 2004/07/14
Author: Stefan Esser [s.esser@ematters.de]
Application: PHP ");

Due to a binary safety problem within the allowed tags handling attacker supplied tags like: or will pass the check and wont get stripped. (magic_quotes_gpc must be Off)

In a perfect world this would be no dangerous problem because such tags are either in the allowed taglist or should get ignored by the browser because they have no meaning in HTML.

In the real world however MS Internet Explorer and Safari filter '\0' characters from the tag and accept them as valid. Quite obvious that this can not only lead to a number of XSS issues on sites that filter dangerous tags with PHP's strip_tags() but also on every other site that filters them with pattern matching and is not necessary running PHP.

According to tests:

- Opera
- Konqueror
- Mozilla
- Mozilla Firefox
- Epiphany

are NOT affected by this.

Proof of Concept

e-matters is not going to release an exploit for this vulnerability to the public.

Disclosure Timeline

26 June 2004 Problem found and fixed in CVS
14 July 2004 Public Disclosure

CVE Information

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0595 to this issue.

Recommendation

Because Internet Explorer is out of all reason still the most used browser fixing this problem within your PHP version is strongly recommended.

Copyright 2004 Stefan Esser. All rights reserved.

PHP blasted with double-barrelled security holes

Posted: Mon Jul 19, 2004 5:05 am
by ner0
Makes me glad I upgraded my php /bigwink.gif' class='bbc_emoticon' alt=';)' />