News: PHP 4.1.2 Windows (Win32)

Posted by: w4z004on 2002/3/13 15:57:02 5781 reads
(News article taken from php.net)

Due to an issue with the Windows binary allowing any user to read or execute the contents of a file directly from the PHP binary, we have delayed the 4.1.2 release of PHP for Windows to allow for this fix. This release also fixes the file upload security problem.

With this new release, we introduce 2 new php.ini settings, which MUST be set to make the binary work. It's worth noting, at this point, that this particular fix only applies to the CGI binary. The SAPI module will still work as expected, and it's use is encouraged.

The new settings are:

cgi.force_redirect 0|1
cgi.redirect_status_env ENV_VAR_NAME

WebServers affected by this vulnerability
It is known that Apache (any version) and iPlanet servers are vulnerable to this issue, however Microsoft IIS is not. Since cgi.force_redirect takes a value of either 1 or 0, (on or off) you should set it to 1 if you are running Apache or iPlanet servers, and to 0 for IIS. If you are unsure of which you need, set it to 1 and see if your scripts execute. You will need to stop and restart your server when you change your php.ini file, for the changes to have effect.

if cgi.force_redirect is turned on, and you are not running under Apache or Netscape (iPlanet) web servers, you MAY need to set an environment variable name that PHP will look for to know it is OK to continue execution. Setting this variable MAY cause security issues, so check what you are doing first.

More information can be found here relating to the form upload exploit that caused the release of 4.1.2 initially.


Downloads:

PHP 4.1.2 zip package [5,824Kb] - 12 March 2002
(CGI binary (with security fixes) plus server API versions for Apache, AOLserver, ISAPI and NSAPI. MySQL support built-in, many extensions included, packaged as zip)

PHP 4.1.2 installer [920Kb] - 12 March 2002
(CGI only (with fixes), MySQL support built-in, packaged as Windows installer to install and configure PHP, and automatically configure IIS, PWS and Xitami, with manual configuration for other servers. N.B. no external extensions included)