papasian.org
http://papasian.org/~dannyp/apcsmash.php.txt CVE-2008-1488
PECL 3.0.x - Alternative PHP Cache Extension 'apc_search_paths()' Remote Buffer Overflow
Record summary
CVE-2008-1488 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in apc.c in Alternative PHP Cache (APC) 3.0.11 through 3.0.16 allows remote attackers to execute arbitrary code via a long filename.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPECL 3.0.x - Alternative PHP Cache Extension 'apc_search_paths()' Remote Buffer OverflowExploitDB exploitby dannypNot analyzed1 file
References
12pecl.php.netConfirmation
http://pecl.php.net/bugs/bug.php?id=13415 29509Third-party advisory
http://secunia.com/advisories/29509 29745Third-party advisory
http://secunia.com/advisories/29745 31082Third-party advisory
http://secunia.com/advisories/31082 GLSA-200804-07Vendor advisory
http://security.gentoo.org/glsa/glsa-200804-07.xml MDVSA-2008:082Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:082 28457vdb entry
http://www.securityfocus.com/bid/28457 apc-apcsearchpaths-bo(41420)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41420 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-1488 FEDORA-2008-6344Vendor advisory
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00548.html FEDORA-2008-6401Vendor advisory
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00582.html