PT-2011-1242 · Php · Php
Publicado
2011-03-19
·
Atualizado
2018-10-30
·
CVE-2011-1467
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
PHP versions prior to 5.3.6
Description
The issue is related to an unspecified vulnerability in the NumberFormatter::setSymbol function in the Intl extension. This vulnerability allows context-dependent attackers to cause a denial of service, resulting in an application crash, via an invalid argument. The vulnerability exists due to insufficient input validation.
Recommendations
For versions prior to 5.3.6, update to version 5.3.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
NumberFormatter::setSymbol function until a patch is available.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Php