Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-0397

Опубликовано: 12 мар. 2010
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

Отчет

This issue was addressed in the php packages as shipped with Red Hat Enterprise Linux 4 and 5 via: https://rhn.redhat.com/errata/RHSA-2010-0919.html

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=573779php: NULL pointer dereference in XML-RPC extension

EPSS

Процентиль: 92%
0.07996
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

nvd
больше 15 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

debian
больше 15 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing m ...

github
около 3 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

oracle-oval
больше 14 лет назад

ELSA-2010-0919: php security update (MODERATE)

EPSS

Процентиль: 92%
0.07996
Низкий

4.3 Medium

CVSS2