PT-2010-4428 · Php+2 · Php+2

Publicado

2010-09-28

·

Atualizado

2024-06-15

·

CVE-2010-2950

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions 5.3.x through 5.3.3
Description A format string vulnerability exists in the phar extension, specifically in stream.c, allowing context-dependent attackers to obtain sensitive information, such as memory contents, and possibly execute arbitrary code. This issue arises from a crafted phar:// URI that is not properly handled by the phar stream flush function, leading to errors in the php stream wrapper log error function.
Recommendations For PHP versions 5.3.x through 5.3.3, consider updating to a version that includes a complete fix for this issue, as the current fix is incomplete. As a temporary workaround, restrict access to the phar extension to minimize the risk of exploitation.

Exploit

Correção

Use of Externally-Controlled Format String

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2012_1046
CVE-2010-2950
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2012:1046
RHSA-2012:1047
RHSA-2012_1046
RHSA-2012_1047

Produtos afetados

Centos
Php
Red Hat