PT-2009-5023 · Php · Php

Maksymilian Arciemowicz

·

Publicado

2009-12-01

·

Atualizado

2018-10-30

·

CVE-2009-2626

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.3.1
Description The issue allows context-specific attackers to obtain sensitive information, such as memory contents, and cause a PHP crash. This is achieved by using the ini set function to declare a variable, then using the ini restore function to restore the variable. The zend restore ini entry cb function in zend ini.c is specifically implicated in this issue.
Recommendations For PHP versions prior to 5.3.1, update to a version that contains a fix for this issue, such as PHP 5.3.1 or later, to prevent the potential for sensitive information disclosure and PHP crashes.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-2626
DSA-1940-1

Produtos afetados

Php