PT-2011-1234 · Php · Php

Published

2011-01-18

·

Updated

2018-10-30

·

CVE-2010-4699

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.3.4
Description The issue is related to the iconv mime decode headers function in the Iconv extension, which does not properly handle unrecognized encodings. This can be exploited by remote attackers to trigger an incomplete output array, potentially bypassing spam detection or having other unspecified impacts. The attack can be carried out via a crafted Subject header in an e-mail message.
Recommendations For versions prior to 5.3.4, update to version 5.3.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the iconv mime decode headers function until a patch is available. Avoid using unrecognized encodings in the Subject header of e-mail messages to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02605
CVE-2010-4699

Affected Products

Php