Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-0421

Опубликовано: 20 мар. 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

0.10-1
hardy

ignored

end of life
karmic

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

ignored

end of life
oneiric

ignored

end of life
precise

not-affected

0.10-1
quantal

not-affected

0.10-1

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

not-affected

5.3.6-11ubuntu1
hardy

released

5.2.4-2ubuntu5.15
karmic

released

5.2.10.dfsg.1-2ubuntu6.9
lucid

released

5.3.2-1ubuntu4.8
maverick

released

5.3.3-1ubuntu9.4
natty

released

5.3.5-1ubuntu7.1
oneiric

not-affected

5.3.6-11ubuntu1
precise

not-affected

5.3.6-11ubuntu1
quantal

not-affected

5.3.6-11ubuntu1

Показывать по

EPSS

Процентиль: 92%
0.09294
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.

nvd
больше 14 лет назад

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.

debian
больше 14 лет назад

The _zip_name_locate function in zip_name_locate.c in the Zip extensio ...

github
около 3 лет назад

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.

CVSS3: 5.3
fstec
больше 14 лет назад

Уязвимость функции _zip_name_locate интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 92%
0.09294
Низкий

4.3 Medium

CVSS2