Re: [Full-Disclosure] Advisory 11/2004: PHP memory_limit remote vulnerability

2004-07-14 Thread Florian Weimer
* Stefan Esser: > Application: PHP <= 4.3.7 >PHP5 <= 5.0.0RC3 > Severity: A vulnerability within PHP allows remote code >execution on PHP servers with activated memory_limit > Risk: Critical Uh-oh. Has anybody got a minimal patch to fix this issue

[Full-Disclosure] Advisory 11/2004: PHP memory_limit remote vulnerability

2004-07-13 Thread Stefan Esser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 e-matters GmbH www.e-matters.de -= Security Advisory =- Advisory: PHP memory_limit remote vulnerability Release Date: 2004/07/14 Last Modified: 2004/07/14 Auth