Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1938

Опубликовано: 23 мая 2011
Источник: redhat
CVSS2: 2.6
EPSS Средний

Описание

Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.

Отчет

Not vulnerable. This issue did not affect the versions of php as shipped with Red Hat Enterprise Linux 4 and 5. It has been addressed in Red Hat Enterprise Linux 5 (php53) and 6 (php).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4phpNot affected
Red Hat Enterprise Linux 5phpNot affected
Red Hat Enterprise Linux 5php53FixedRHSA-2011:142302.11.2011
Red Hat Enterprise Linux 6phpFixedRHSA-2011:142302.11.2011

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=709067php: stack-based buffer overflow in socket_connect()

EPSS

Процентиль: 98%
0.50514
Средний

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
около 14 лет назад

Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.

nvd
около 14 лет назад

Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.

debian
около 14 лет назад

Stack-based buffer overflow in the socket_connect function in ext/sock ...

github
около 3 лет назад

Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.

oracle-oval
больше 13 лет назад

ELSA-2011-1423: php53 and php security update (MODERATE)

EPSS

Процентиль: 98%
0.50514
Средний

2.6 Low

CVSS2