Multipl e vulnerabilities have been identified in PHP, which could be exploited by remote attackers to execute arbitrary commands.It has been seen that a buffer overflow error occurs in the HTML entity encoder when handling a specially crafted data passed to the "htmlentities " and "htmlspecialchars " functions. The vulnerability could be exploited by remote attackers to cause a denial of service or compromise a vulnerable server.
It has been seen that it is possible to bypass "safe_mode" and "open_basedir" restrictions in PHP. This is due to an an error in the cURL extension. This could allow remote attackers to bypass certain security restrictions on the vulnerable system. A buffer overflow vulnerability has been reported in the "str_repeat " and "wordwrap " functions on 64bit systems, which could be exploited by attackers or malicious users to execute arbitrary commands on the vulnerable system.
The information provided herein is on "as is" basis, without warranty of any kind.