Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function.
Link | Tags |
---|---|
http://retrogod.altervista.org/php_446_crack_opendict_local_bof.html | exploit |
https://www.exploit-db.com/exploits/3431 | exploit |
http://securityreason.com/securityalert/2405 | third party advisory |
http://www.securityfocus.com/archive/1/462226/100/0/threaded | mailing list |