Описание
The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 5.1.2-1ubuntu3.19 |
devel | not-affected | 5.3.3-1ubuntu6 |
hardy | released | 5.2.4-2ubuntu5.12 |
intrepid | ignored | end of life, was needed |
jaunty | released | 5.2.6.dfsg.1-3ubuntu4.6 |
karmic | released | 5.2.10.dfsg.1-2ubuntu6.5 |
lucid | not-affected | 5.3.2-1ubuntu4.2 |
upstream | released | 5.3.3 |
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.
The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.
The xmlrpc extension in PHP 5.3.1 does not properly handle a missing m ...
The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.
EPSS
5 Medium
CVSS2