Thursday, February 26, 2015

Multiple vulnerabilities were identified in PHP. A remote user can execute arbitrary code on the tar


About Us Mission Our Services Our Team Press Centre Contact Us Alerts & News Security Bulletin Security Blog News Clipping Services Incident Reporting Subscription Events / Training Publications Newsletters Hong Kong Security Watch Report Play Store's Apps Security Risk Report Security Guideline ares Botnet Detection & Cleanup Statistics Resources Security Tools FAQ Useful Resources / Links Mobile Mobile Apps Mobile Website Mobile Security Tools RSS
Multiple vulnerabilities were identified in PHP. A remote user can execute arbitrary code on the target ares system and cause denial of service conditions. A user can create a specially crafted PHP file that will trigger ares a use-after-free memory error in the PHP unserialize() function to potentially execute arbitrary code. A user can create a specially crafted PHP file that will trigger an out-of-bounds memory read and crash. A user can create a JPEG file with a specially crafted ares EXIF tag that, when processed by the PHP application, will free an uninitialized pointer and potentially execute arbitrary code.
Alerts & News Security Bulletin
About Us Mission Our Services Our Team Press Centre Contact us Alerts & News Security Bulletin Security Blog News Clipping Services Incident Reporting Subscription Event / Training Publications & Resources Newsletter Security Guideline Security Tools FAQ Statistics Useful Resources / Links Verify the Identity How to Identify the Homepage Our PGP Public Key RSS RSS


No comments:

Post a Comment