|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
PHP contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when multiple virtual hosts are served from an Apache server, and the same child process is used to access different virtual hosts, which will leak settings between virtual hosts resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Authentication Management,
Information Disclosure
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 4.3.5RC2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
PHP
 |
4.0.6 |
4.1.0 |
4.1.1 |
4.2.0 |
4.2.1 |
4.2.2 |
4.3.0 |
4.3.1 |
4.3.4 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|