Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-4721

Опубликовано: 06 июл. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6

Описание

The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.

РелизСтатусПримечание
devel

released

5.5.12+dfsg-2ubuntu3
esm-infra-legacy/trusty

not-affected

5.5.9+dfsg-1ubuntu4.3
lucid

released

5.3.2-1ubuntu4.26
precise

released

5.3.10-1ubuntu3.13
saucy

released

5.5.3+dfsg-1ubuntu2.6
trusty

released

5.5.9+dfsg-1ubuntu4.3
trusty/esm

not-affected

5.5.9+dfsg-1ubuntu4.3
upstream

needs-triage

Показывать по

EPSS

Процентиль: 93%
0.09887
Низкий

2.6 Low

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.

nvd
почти 11 лет назад

The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.

debian
почти 11 лет назад

The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 ...

github
около 3 лет назад

The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.

CVSS3: 5.3
fstec
почти 11 лет назад

Уязвимость функции phpinfo (ext/standard/info.c) интерпретатора языка программирования PHP, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 93%
0.09887
Низкий

2.6 Low

CVSS2