Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-4698

Опубликовано: 29 июн. 2014
Источник: redhat
CVSS2: 2.1

Описание

Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted ArrayIterator usage within applications in certain web-hosting environments.

A use-after-free flaw was found in the way PHP handled certain ArrayIterators. A malicious script author could possibly use this flaw to disclose certain portions of server memory.

Отчет

This issue did not affect the versions of php as shipped with Red Hat Enterprise Linux 5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1phpWill not fix
Red Hat Enterprise Linux 5phpNot affected
Red Hat OpenShift Enterprise 2phpWill not fix
Red Hat Enterprise Linux 5php53FixedRHSA-2014:132630.09.2014
Red Hat Enterprise Linux 6phpFixedRHSA-2014:132630.09.2014
Red Hat Enterprise Linux 7phpFixedRHSA-2014:132730.09.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6php54-phpFixedRHSA-2014:176530.10.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6php55-phpFixedRHSA-2014:176630.10.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSphp54-phpFixedRHSA-2014:176530.10.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSphp55-phpFixedRHSA-2014:176630.10.2014

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1120259php: ArrayIterator use-after-free due to object change during sorting

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted ArrayIterator usage within applications in certain web-hosting environments.

nvd
почти 11 лет назад

Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted ArrayIterator usage within applications in certain web-hosting environments.

debian
почти 11 лет назад

Use-after-free vulnerability in ext/spl/spl_array.c in the SPL compone ...

github
около 3 лет назад

Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted ArrayIterator usage within applications in certain web-hosting environments.

fstec
почти 11 лет назад

Уязвимость программного обеспечения PHP, позволяющая злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

2.1 Low

CVSS2