Intrusion Prevention

PHP.HTTP.POST.Incorrect.MIME.Header

Description

It indicates a possible exploit of a MIME header parsing vulnerability in PHP 4.2.0 and 4.2.1 that may allow remote attackers to cause a denial of service and possibly execute arbitrary code. The vulnerability can be exploited by sending an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed.

Affected Products

PHP 4.2.0 and 4.2.1

Impact

Denial of Service or Compromise of the affected system.

Recommended Actions

Upgrade to PHP PHP 4.2.2 or later.

CVE References

CVE-2002-0717