Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-4657

Опубликовано: 13 нояб. 2019
Источник: debian
EPSS Низкий

Описание

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php5fixed5.4.4-1package
php5no-dsasqueezepackage

Примечания

  • https://bugzilla.gnome.org/show_bug.cgi?id=631551

  • Not sure when this was initially fixed, tested with the initial Wheezy version 5.4.4

  • and the reproducer from https://bugs.launchpad.net/php/%2Bbug/655442

EPSS

Процентиль: 71%
0.00691
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

redhat
почти 15 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
nvd
почти 6 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
github
больше 3 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
fstec
почти 6 лет назад

Уязвимость компонента XMLWriter интерпретатора языка программирования PHP, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 71%
0.00691
Низкий