PT-2010-5485 · Php+1 · Php+1

Maksymilian Arciemowicz

·

Publicado

2010-12-06

·

Atualizado

2018-10-30

·

CVE-2010-4409

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions PHP versions 5.3.3 and earlier
Description The issue is related to an integer overflow in the NumberFormatter::getSymbol (also known as numfmt get symbol) function. This allows context-dependent attackers to cause a denial of service, resulting in an application crash, by providing an invalid argument.
Recommendations For PHP versions 5.3.3 and earlier, consider upgrading to a version where this issue is fixed, as using an invalid argument in the NumberFormatter::getSymbol function can lead to a denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-4409
SUSE-SU-2012_0108-1
SUSE-SU-2012_0109-1
SUSE-SU-2013_0051-1

Produtos afetados

Php
Suse