LWN.net Logo

php: integer overflow

Package(s):php CVE #(s):CVE-2006-4812
Created:October 5, 2006 Updated:October 30, 2006
Description: The PHP memory handling routines have an integer overflow vulnerability. A remote attacker can use a script to cause memory allocation based on untrusted data, allowing arbitrary code to be executed as the apache user.
Alerts:
Gentoo 200610-14 2006-10-30
Fedora FEDORA-2006-1024 2006-10-19
OpenPKG OpenPKG-SA-2006.023 2006-10-17
Ubuntu USN-362-1 2006-10-10
SuSE SUSE-SA:2006:059 2006-10-09
Mandriva MDKSA-2006:180 2006-10-05
Red Hat RHSA-2006:0688-01 2006-10-05
Red Hat RHSA-2006:0708-01 2006-10-05

(Log in to post comments)

php: integer overflow

Posted Aug 6, 2007 17:51 UTC (Mon) by kreutzm (guest, #4700) [Link]

Both Debian sarge and etch are not vulnerable.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds