PT-2004-2018 · Php+2 · Php+2

Stefan Esser

·

Published

2004-12-22

·

Updated

2018-10-30

·

CVE-2004-1019

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: PHP versions prior to 4.3.10 PHP 5.x versions up to 5.0.2
Description: The issue allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function, potentially triggering information disclosure, double-free, and negative reference index array underflow results.
Recommendations: For PHP versions prior to 4.3.10, update to version 4.3.10 or later. For PHP 5.x versions up to 5.0.2, update to version 5.0.3 or later. As a temporary workaround, consider restricting the use of the unserialize function to trusted data only until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-1019
RHSA-2004:687
RHSA-2005:032
RHSA-2005_032
SUSE-SU-2016:1638-1

Affected Products

Php
Red Hat
Suse