PT-2011-1234 · Php · Php

Publicado

2011-01-18

·

Atualizado

2018-10-30

·

CVE-2010-4699

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.3.4
Description The issue is related to the iconv mime decode headers function in the Iconv extension, which does not properly handle unrecognized encodings. This can be exploited by remote attackers to trigger an incomplete output array, potentially bypassing spam detection or having other unspecified impacts. The attack can be carried out via a crafted Subject header in an e-mail message.
Recommendations For versions prior to 5.3.4, update to version 5.3.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the iconv mime decode headers function until a patch is available. Avoid using unrecognized encodings in the Subject header of e-mail messages to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02605
CVE-2010-4699

Produtos afetados

Php