Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > MOPB Starts with 3 Bugs

    Following the footsteps of MOAB, MOKB, MOBB, the Hardened-PHP Project declares March as the Month of PHP Bugs and promptly publishes three PHP flaws, one of which comes with an exploit to boot:

    • PHP Variable Destructor Deep Recursion Stack Overflow
      - destruction of deeply nested PHP arrays can exhaust all available stack leading to remotely triggerable crashes

    • PHP Executor Deep Recursion Stack Overflow (CVE-2006-1549)
      - deep recursion of PHP userland code can exhaust all available stack sometimes leading to a remotely triggerable crash

    • PHP 4 Userland ZVAL Reference Counter Overflow Vulnerability
      - PHP 4 userland code is able to overflow the internal 16bit zval reference counter by creating many references to a variable leading to an exploitable double dtor condition
      - comes with an exploit

    The project clarifies that it is not going after bugs in the PHP language itself, rather it aims to divulge flaws and security vulnerabilities in the PHP core, the Zend Engine, and PHP extensions.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    One Response to “MOPB Starts with 3 Bugs”

    Trackbacks

    1. Chris Mosby at myITforum.com : MOPB Starts with 3 Bugs - TrendLabs | Anti-Malware Blog - by Trend Micro


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice