PT-2003-1921 · Php+1 · Php+1

Stefan Esser

·

Publicado

2003-10-15

·

Atualizado

2018-10-30

·

CVE-2003-0861

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 4.3.3
Description The issue concerns integer overflows in two components: (1) the base64 encode function and (2) the GD library. These overflows may result in the corruption of sensitive regions of memory. The estimated number of potentially affected devices worldwide and details about real-world incidents where this issue was exploited are not specified.
Recommendations For PHP versions prior to 4.3.3, update to version 4.3.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the base64 encode function and the GD library until a patch is available. Avoid using these components in sensitive operations to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0861

Produtos afetados

Gd Library
Php