Korean
<< Back
VID 22558
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description According to its banner, the version of PHP installed on the remote host is 5.3.x earlier than 5.3.15, and is, therefore, potentially affected by the following vulnerabilities :

- An unspecified overflow vulnerability exists in the function '_php_stream_scandir' in the file 'main/streams/streams.c'. (CVE-2012-2688)

- An unspecified error exists that can allow the 'open_basedir' constraint to be bypassed. (CVE-2012-3365)

* Note: This check solely relied on the version number of the remote WebLogic server to assess this vulnerability, so this might be a false positive.

* References:
http://www.php.net/ChangeLog-5.php#5.3.15


* Platforms Affected:
PHP Prior to 5.3.15
Any operating system Any version
Recommendation Upgrade to the latest version of PHP (5.3.15 or later), available from the Mozilla Web site at http://www.php.net/downloads.php
Related URL CVE-2012-2688,CVE-2012-3365 (CVE)
Related URL 54612 (SecurityFocus)
Related URL (ISS)