PT-2014-4434 · Php · Php

Publicado

2014-02-18

·

Atualizado

2014-03-08

·

CVE-2014-2020

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP versions 5.5.x before 5.5.9
Description The issue allows remote attackers to obtain sensitive information by using incorrect data types, such as a string or array in place of a numeric data type. This can be demonstrated by an imagecrop function call with a string for the x dimension value.
Recommendations For PHP versions 5.5.x before 5.5.9, update to version 5.5.9 or later to resolve the issue. As a temporary workaround, consider validating and sanitizing user input to ensure correct data types are used, especially for functions like imagecrop that expect numeric values.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-2020

Produtos afetados

Php