PHP contains a flaw that may allow a context-dependent attacker to gain elevated privileges. The issue is due to the in parameter of the sqlite_decode_binary function in the bundled sqlite library not properly sanitizing user-supplied input. By supplying crafted input, an attacker can trigger a buffer overflow and potentially execute arbitrary code.
Classification
Location:
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Disclosure:
Vendor Verified
Solution
Upgrade to version 5.2.3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
This issue was originally patched in PHP 5.2.1 but later the patch was enhanced to better work with a non-bundled sqlite2 lib.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.