PT-2011-1243 · Php · Php

Vincent Danen

·

Published

2011-03-19

·

Updated

2024-06-15

·

CVE-2011-0421

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.3.6
Description The issue is related to the zip name locate function in the Zip extension, which does not properly handle a ZIPARCHIVE::FL UNCHANGED argument. This might allow attackers to cause a denial of service via an empty ZIP archive that is processed with a locateName or statName operation. The vulnerability is associated with a NULL pointer dereference, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For PHP versions prior to 5.3.6, update to version 5.3.6 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the ZIPARCHIVE::FL UNCHANGED argument in the zip name locate function until a patch is available. Restrict access to the Zip extension to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02617
CVE-2011-0421
DSA-2266-1
OPENSUSE-SU-2024:10113-1
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1

Affected Products

Php