Lucene search

K
ubuntuUbuntuUSN-40-1
HistoryDec 17, 2004 - 12:00 a.m.

PHP vulnerabilities

2004-12-1700:00:00
ubuntu.com
36

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.9 High

AI Score

Confidence

High

0.134 Low

EPSS

Percentile

95.6%

Releases

  • Ubuntu 4.10

Details

Stefan Esser reported several buffer overflows in PHP’s variable unserializing
handling. These could allow an attacker to execute arbitrary code on the server
with the PHP interpreter’s privileges by sending specially crafted input
strings (form data, cookie values, and similar).

Additionally, Ilia Alshanetsky discovered a buffer overflow in the
exif_read_data() function. Attackers could execute arbitrary code on the server
by sending a JPEG image with a very long “sectionname” value to PHP
applications that support image uploads.

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.9 High

AI Score

Confidence

High

0.134 Low

EPSS

Percentile

95.6%