PT-2012-1221 · Php+3 · Php+3

Published

2012-05-11

·

Updated

2024-06-15

·

CVE-2012-2688

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.3.15 PHP versions 5.4.x prior to 5.4.5
Description The issue is related to a buffer overflow in the dynamic memory of the php stream scandir function in PHP. This could allow a remote attacker to execute arbitrary code. The vulnerability is associated with an "overflow" and has remote attack vectors.
Recommendations For PHP versions prior to 5.3.15, update to version 5.3.15 or later. For PHP versions 5.4.x prior to 5.4.5, update to version 5.4.5 or later.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

APACHEPHPCGI3DRCECHECK
APACHEPHPCGIRCECHECK
BDU:2022-02620
CESA-2013_0514
CVE-2012-2688
DSA-2527-1
ELSA-2013-0514
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2013:0514
RHSA-2013:1307
RHSA-2013:1814
RHSA-2013_0514
RHSA-2013_1307
RHSA-2013_1814
SUSE-SU-2012_1033-1
SUSE-SU-2012_1034-1

Affected Products

Centos
Php
Red Hat
Suse