CVE-2014-4721
published 2014-07-06CVE-2014-4721: The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW…
PriorityP416low2.6CVSS 2.0
AVNACHAuNCPINAN
EPSS
5.87%
92.4th percentile
The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| php | php | >= 5.3.0 < 5.3.29 | 5.3.29 |
| php | php | >= 5.4.0 < 5.4.30 | 5.4.30 |
| php | php | >= 5.5.0 < 5.5.14 | 5.5.14 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.3 | 5.5.9+dfsg-1ubuntu4.3 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2014-07-09·CVSS 6.5
CVE-2014-0207 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
Francisco Alonso discovered that the PHP Fileinfo component incorrectly
handled certain CDF documents. A remote attacker could use this issue to
cause PHP to hang or crash, resulting in a denial of service.
(CVE-2014-0207, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Stefan Esser discovered that PHP incorrectly handled unserializing SPL
extension objects. An attacker could use this issue to execute arbitrary
code. (CVE-2014-3515)
It was discovered that PHP incorrectly handled certain SPL Iterators. An
attacker could use this issue to cause PHP to crash, resulting in a denial
of service. (CVE-2014-4670)
It was discovered that PHP incorrectly handled certain ArrayIterators. An
attacker could us
Red Hat
php: type confusion issue in phpinfo() leading to information leak
vendor_redhat·2014-06-23·CVSS 2.6
CVE-2014-4721 [LOW] CWE-843 php: type confusion issue in phpinfo() leading to information leak
php: type confusion issue in phpinfo() leading to information leak
The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.
A type confusion issue was found in PHP's phpinfo() function. A malicious script author could possibly use this flaw to disclose certain portions of server memory.
Statement: Red Hat classi
GHSA
GHSA-crxc-8h2p-6c8g: The phpinfo implementation in ext/standard/info
ghsa_unreviewed·2022-05-17
CVE-2014-4721 [LOW] CWE-200 GHSA-crxc-8h2p-6c8g: The phpinfo implementation in ext/standard/info
The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.
OSV
php5 vulnerabilities
osv·2014-07-09·CVSS 6.5
CVE-2014-0207 [MEDIUM] php5 vulnerabilities
php5 vulnerabilities
Francisco Alonso discovered that the PHP Fileinfo component incorrectly
handled certain CDF documents. A remote attacker could use this issue to
cause PHP to hang or crash, resulting in a denial of service.
(CVE-2014-0207, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487)
Stefan Esser discovered that PHP incorrectly handled unserializing SPL
extension objects. An attacker could use this issue to execute arbitrary
code. (CVE-2014-3515)
It was discovered that PHP incorrectly handled certain SPL Iterators. An
attacker could use this issue to cause PHP to crash, resulting in a denial
of service. (CVE-2014-4670)
It was discovered that PHP incorrectly handled certain ArrayIterators. An
attacker could use this issue to cause PHP to crash, resulting in a denial
o
OSV
CVE-2014-4721: The phpinfo implementation in ext/standard/info
osv·2014-07-06·CVSS 2.6
CVE-2014-4721 [LOW] CVE-2014-4721: The phpinfo implementation in ext/standard/info
The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4721 php: type confusion issue in phpinfo() leading to information leak
bugzilla·2014-07-07·CVSS 2.6
CVE-2014-4721 [LOW] CVE-2014-4721 php: type confusion issue in phpinfo() leading to information leak
CVE-2014-4721 php: type confusion issue in phpinfo() leading to information leak
Stefan Esser discovered a type confusion issue affecting phpinfo(). Setting certain variables before running phpinfo() could allow a local attacker to leak memory from an arbitrary location. This could be an issue remotely in shared hosting environments if PHP code can be injected. The following post demonstrates reading an SSL private key in an environment using PHP 5.3, mod_php, and mod_ssl:
https://www.sektioneins.de/en/blog/14-07-04-phpinfo-infoleak.html
References:
https://bugs.php.net/bug.php?id=67498
http://git.php.net/?p=php-src.git;a=commitdiff;h=3804c0d00fa6e629173fb1c8c61f8f88d5fe39b9
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1116663]
---
*** Bug 1116532
Bugzilla
CVE-2014-4721 php: type confusion issue in phpinfo() leading to information leak [fedora-all]
bugzilla·2014-07-07·CVSS 2.6
CVE-2014-4721 [LOW] CVE-2014-4721 php: type confusion issue in phpinfo() leading to information leak [fedora-all]
CVE-2014-4721 php: type confusion issue in phpinfo() leading to information leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue a
http://lists.opensuse.org/opensuse-updates/2014-07/msg00035.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00046.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://secunia.com/advisories/54553http://secunia.com/advisories/59794http://secunia.com/advisories/59831http://twitter.com/mikispag/statuses/485713462258302976http://www-01.ibm.com/support/docview.wss?uid=swg21683486http://www.debian.org/security/2014/dsa-2974http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.php.net/ChangeLog-5.phphttps://bugs.php.net/bug.php?id=67498https://www.sektioneins.de/en/blog/14-07-04-phpinfo-infoleak.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00035.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00046.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://secunia.com/advisories/54553http://secunia.com/advisories/59794http://secunia.com/advisories/59831http://twitter.com/mikispag/statuses/485713462258302976http://www-01.ibm.com/support/docview.wss?uid=swg21683486http://www.debian.org/security/2014/dsa-2974http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.php.net/ChangeLog-5.phphttps://bugs.php.net/bug.php?id=67498https://www.sektioneins.de/en/blog/14-07-04-phpinfo-infoleak.html
2014-07-06
Published