Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-3292
HistorySep 22, 2009 - 12:00 a.m.

CVE-2009-3292

2009-09-2200:00:00
ubuntu.com
ubuntu.com
19

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.018

Percentile

88.2%

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has
unknown impact and attack vectors related to “missing sanity checks around
exif processing.”

Bugs

Notes

Author Note
mdeslaur denial of service
OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchphp5< 5.1.2-1ubuntu3.17UNKNOWN
ubuntu8.04noarchphp5< 5.2.4-2ubuntu5.9UNKNOWN
ubuntu8.10noarchphp5< 5.2.6-2ubuntu4.5UNKNOWN
ubuntu9.04noarchphp5< 5.2.6.dfsg.1-3ubuntu4.4UNKNOWN
ubuntu9.10noarchphp5< 5.2.10.dfsg.1-2ubuntu6.3UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.018

Percentile

88.2%