Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4113

Опубликовано: 11 июл. 2013
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

Отчет

This issue does not affect the version of php54 as shipped with Red Hat Software Collections 1.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7phpNot affected
Red Hat Software Collectionsphp54-phpNot affected
Red Hat Enterprise Linux 3 Extended Lifecycle SupportphpFixedRHSA-2013:106315.07.2013
Red Hat Enterprise Linux 4 Extended Lifecycle SupportphpFixedRHSA-2013:106315.07.2013
Red Hat Enterprise Linux 5phpFixedRHSA-2013:104912.07.2013
Red Hat Enterprise Linux 5php53FixedRHSA-2013:105012.07.2013
Red Hat Enterprise Linux 5.3 Long LifephpFixedRHSA-2013:106115.07.2013
Red Hat Enterprise Linux 5.6 EUS - Server OnlyphpFixedRHSA-2013:106115.07.2013
Red Hat Enterprise Linux 5.6 EUS - Server Onlyphp53FixedRHSA-2013:106215.07.2013
Red Hat Enterprise Linux 6phpFixedRHSA-2013:104912.07.2013

Показывать по

Дополнительная информация

Статус:

Critical
https://bugzilla.redhat.com/show_bug.cgi?id=983689php: xml_parse_into_struct buffer overflow when parsing deeply nested XML

EPSS

Процентиль: 92%
0.09498
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

nvd
около 12 лет назад

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

debian
около 12 лет назад

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing ...

github
около 3 лет назад

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

oracle-oval
около 12 лет назад

ELSA-2013-1050: php53 security update (CRITICAL)

EPSS

Процентиль: 92%
0.09498
Низкий

6.8 Medium

CVSS2