CERT-In Advisory CIAD-2006-40
Multiple Vulnerabilities in Linux
Original issue date:
November 07, 2006
Severity Rating: High
Systems Affected
- RPM Package Manager 4.x
- PHP version 5.1.6 and prior
- PHP version 4.4.4 and prior
- PHP-Nuke version 7.9 and prior
Overview
Multiple vulnerabilities have been reported in Linux which could be exploited by attackers to compromise the vulnerable system or bypass certain security restrictions.
Description
1. RPM Buffer Overflow Vulnerability ( CVE-2006-5466 )
A vulnerability has been reported in RPM package due to a buffer overflow error in the "showQueryPackage()" [lib/query.c] function when displaying results of a query with certain locales set (e.g. ru_RU.UTF-8), which could be exploited by remote attackers to compromise a vulnerable system while processing a specially crafted RPM packages. This may allow remote attackers to execute arbitrary commands on the vulnerable system.
2. PHP Remote Command Execution Vulnerabilities ( CVE-2006-5465 )
Multipl e vulnerabilities have been identified in PHP, which could be exploited by remote attackers to execute arbitrary commands.
It has been seen that a buffer overflow error occurs in the HTML entity encoder when handling a specially crafted data passed to the "htmlentities()" and "htmlspecialchars()" functions. The vulnerability could be exploited by remote attackers to cause a denial of service or compromise a vulnerable server.
It has been seen that it is possible to bypass "safe_mode" and "open_basedir" restrictions in PHP. This is due to an an error in the cURL extension. This could allow remote attackers to bypass certain security restrictions on the vulnerable system.
A buffer overflow vulnerability has been reported in the "str_repeat()" and "wordwrap()" functions on 64bit systems, which could be exploited by attackers or malicious users to execute arbitrary commands on the vulnerable system.
Solution
Apply appropriate patches suggested by vendor
References
Bugzilla
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=212833
Secunia
http://secunia.com/advisories/22740/
http://secunia.com/advisories/22653/
http://secunia.com/advisories/22617/
FrSIRT
http://www.frsirt.com/english/advisories/2006/4317
http://www.frsirt.com/english/advisories/2006/4350
CVE Name
CVE-2006-5466
CVE-2006-5465 Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information

Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In)
Ministry of Communications and Information Technology
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003

|