Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-4153

Опубликовано: 18 янв. 2012
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

РелизСтатусПримечание
devel

not-affected

5.3.10-1ubuntu1
hardy

released

5.2.4-2ubuntu5.22
lucid

released

5.3.2-1ubuntu4.13
maverick

released

5.3.3-1ubuntu9.9
natty

released

5.3.5-1ubuntu7.6
oneiric

released

5.3.6-13ubuntu3.5
upstream

needs-triage

Показывать по

EPSS

Процентиль: 88%
0.04254
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 13 лет назад

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

nvd
больше 13 лет назад

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

debian
больше 13 лет назад

PHP 5.3.8 does not always check the return value of the zend_strndup f ...

github
около 3 лет назад

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

oracle-oval
почти 13 лет назад

ELSA-2012-1045: php security update (MODERATE)

EPSS

Процентиль: 88%
0.04254
Низкий

5 Medium

CVSS2

Уязвимость CVE-2011-4153