PT-2011-1234 · Php · Php
Publicado
2011-01-18
·
Atualizado
2018-10-30
·
CVE-2010-4699
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PHP versions prior to 5.3.4
Description
The issue is related to the iconv mime decode headers function in the Iconv extension, which does not properly handle unrecognized encodings. This can be exploited by remote attackers to trigger an incomplete output array, potentially bypassing spam detection or having other unspecified impacts. The attack can be carried out via a crafted Subject header in an e-mail message.
Recommendations
For versions prior to 5.3.4, update to version 5.3.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the iconv mime decode headers function until a patch is available. Avoid using unrecognized encodings in the Subject header of e-mail messages to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Php