Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-4657

Опубликовано: 13 нояб. 2019
Источник: debian
EPSS Низкий

Описание

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php5fixed5.4.4-1package
php5no-dsasqueezepackage

Примечания

  • https://bugzilla.gnome.org/show_bug.cgi?id=631551

  • Not sure when this was initially fixed, tested with the initial Wheezy version 5.4.4

  • and the reproducer from https://bugs.launchpad.net/php/%2Bbug/655442

EPSS

Процентиль: 81%
0.0157
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

redhat
больше 14 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
nvd
больше 5 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
github
около 3 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
fstec
больше 5 лет назад

Уязвимость компонента XMLWriter интерпретатора языка программирования PHP, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 81%
0.0157
Низкий