PT-2004-2018 · Php+2 · Php+2

Stefan Esser

·

Publicado

2004-12-22

·

Atualizado

2018-10-30

·

CVE-2004-1019

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: PHP versions prior to 4.3.10 PHP 5.x versions up to 5.0.2
Description: The issue allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function, potentially triggering information disclosure, double-free, and negative reference index array underflow results.
Recommendations: For PHP versions prior to 4.3.10, update to version 4.3.10 or later. For PHP 5.x versions up to 5.0.2, update to version 5.0.3 or later. As a temporary workaround, consider restricting the use of the unserialize function to trusted data only until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-1019
RHSA-2004:687
RHSA-2005:032
RHSA-2005_032
SUSE-SU-2016:1638-1

Produtos afetados

Php
Red Hat
Suse