Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4113

Опубликовано: 11 июл. 2013
Источник: redhat
CVSS2: 6.8

Описание

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

Отчет

This issue does not affect the version of php54 as shipped with Red Hat Software Collections 1.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7phpNot affected
Red Hat Software Collectionsphp54-phpNot affected
Red Hat Enterprise Linux 3 Extended Lifecycle SupportphpFixedRHSA-2013:106315.07.2013
Red Hat Enterprise Linux 4 Extended Lifecycle SupportphpFixedRHSA-2013:106315.07.2013
Red Hat Enterprise Linux 5phpFixedRHSA-2013:104912.07.2013
Red Hat Enterprise Linux 5php53FixedRHSA-2013:105012.07.2013
Red Hat Enterprise Linux 5.3 Long LifephpFixedRHSA-2013:106115.07.2013
Red Hat Enterprise Linux 5.6 EUS - Server OnlyphpFixedRHSA-2013:106115.07.2013
Red Hat Enterprise Linux 5.6 EUS - Server Onlyphp53FixedRHSA-2013:106215.07.2013
Red Hat Enterprise Linux 6phpFixedRHSA-2013:104912.07.2013

Показывать по

Дополнительная информация

Статус:

Critical
https://bugzilla.redhat.com/show_bug.cgi?id=983689php: xml_parse_into_struct buffer overflow when parsing deeply nested XML

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

nvd
больше 12 лет назад

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

debian
больше 12 лет назад

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing ...

github
больше 3 лет назад

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

oracle-oval
больше 12 лет назад

ELSA-2013-1050: php53 security update (CRITICAL)

6.8 Medium

CVSS2