[39009] in bugtraq
Re: [SECURITY] [DSA 729-1] New PHP4 packages fix denial of service
daemon@ATHENA.MIT.EDU (John GALLET)
Fri May 27 16:41:53 2005
Date: Fri, 27 May 2005 10:24:43 +0200 (CEST)
From: John GALLET <john.gallet@wanadoo.fr>
To: bugtraq@securityfocus.com
In-Reply-To: <m1DbGWj-000oqqC@finlandia.Infodrom.North.DE>
Message-ID: <Pine.LNX.4.44.0505271021400.27122-100000@ns2261.ovh.net>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Hi there,
> An iDEFENSE researcher discovered two problems in the image processing
> functions of PHP, a server-side, HTML-embedded scripting language, of
> which one is present in woody as well. When reading a JPEG image, PHP
> can be tricked into an endless loop due to insufficient input
> validation.
I don't see anything in the latest change logs, could anyone please point
me to more information about this error ? Is it located in the GD php
extension ?
Sincerely,
JG