Lucene search

K
freebsdFreeBSD3FD040BE-4F0B-11E1-9E32-0025900931F8
HistoryFeb 02, 2012 - 12:00 a.m.

php -- arbitrary remote code execution vulnerability

2012-02-0200:00:00
vuxml.freebsd.org
17

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.865 High

EPSS

Percentile

98.6%

Secunia reports:

A vulnerability has been reported in PHP, which can be exploited
by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a logic error within the
โ€œphp_register_variable_ex()โ€ function (php_variables.c) when
hashing form posts and updating a hash table, which can be
exploited to execute arbitrary code.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchphp5=ย 5.3.9UNKNOWN
FreeBSDanynoarchphp5<ย 5.3.10UNKNOWN

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.865 High

EPSS

Percentile

98.6%