PT-2011-1238 · Php · Php

Publicado

2011-03-19

·

Atualizado

2018-10-30

·

CVE-2011-1464

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.3.6
Description The issue is related to a buffer overflow in the strval function, which can be triggered when the precision configuration option has a large value. This might allow attackers to cause a denial of service, resulting in an application crash, by providing a small numerical value in the argument. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For PHP versions prior to 5.3.6, update to version 5.3.6 or later to resolve the issue. As a temporary workaround, consider restricting the precision configuration option to a smaller value to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02610
CVE-2011-1464
DSA-2408-1

Produtos afetados

Php