[27014] in bugtraq

home help back first fref pref prev next nref lref last post

Re: PHP fopen() CRLF Injection

daemon@ATHENA.MIT.EDU (Ulf Harnhammar)
Thu Sep 12 13:03:57 2002

Date: Thu, 12 Sep 2002 18:32:36 +0200 (CEST)
From: Ulf Harnhammar <ulfh@update.uu.se>
To: bugtraq@securityfocus.com
In-Reply-To: <Pine.LNX.4.21.0209092317170.31195-100000@Tempo.Update.UU.SE>
Message-ID: <Pine.LNX.4.21.0209121828010.14466-100000@Tempo.Update.UU.SE>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII

This issue has now been fixed in their CVS repository. This is the
patch that they used:

http://cvs.php.net/diff.php/php4/ext/standard/url.c?r1=1.51&r2=1.52&ty=u&Horde=0

// Ulf Harnhammar
ulfh@update.uu.se
http://www.metaur.nu/


On Mon, 9 Sep 2002, Ulf Harnhammar wrote:

> PHP fopen() CRLF Injection
> 
> 
> SUMMARY:
> 
> fopen(), file() and other functions in PHP have a vulnerability
> that makes it possible to add extra HTTP headers to HTTP
> queries. Attackers may use it to escape certain restrictions,
> like what host to access on a web server. In some cases, this
> vulnerability even opens up for arbitrary net connections, turning
> some PHP scripts into proxies and open mail relays.


home help back first fref pref prev next nref lref last post