Описание
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
Отчет
This issue does not affect the version of php54 as shipped with Red Hat Software Collections 1.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз | 
|---|---|---|---|---|
| Red Hat Enterprise Linux 7 | php | Not affected | ||
| Red Hat Software Collections | php54-php | Not affected | ||
| Red Hat Enterprise Linux 3 Extended Lifecycle Support | php | Fixed | RHSA-2013:1063 | 15.07.2013 | 
| Red Hat Enterprise Linux 4 Extended Lifecycle Support | php | Fixed | RHSA-2013:1063 | 15.07.2013 | 
| Red Hat Enterprise Linux 5 | php | Fixed | RHSA-2013:1049 | 12.07.2013 | 
| Red Hat Enterprise Linux 5 | php53 | Fixed | RHSA-2013:1050 | 12.07.2013 | 
| Red Hat Enterprise Linux 5.3 Long Life | php | Fixed | RHSA-2013:1061 | 15.07.2013 | 
| Red Hat Enterprise Linux 5.6 EUS - Server Only | php | Fixed | RHSA-2013:1061 | 15.07.2013 | 
| Red Hat Enterprise Linux 5.6 EUS - Server Only | php53 | Fixed | RHSA-2013:1062 | 15.07.2013 | 
| Red Hat Enterprise Linux 6 | php | Fixed | RHSA-2013:1049 | 12.07.2013 | 
Показывать по
Дополнительная информация
Статус:
6.8 Medium
CVSS2
Связанные уязвимости
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing ...
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
6.8 Medium
CVSS2