LWN.net Logo

php: multiple vulnerabilities

Package(s):php CVE #(s):CVE-2010-3710 CVE-2010-3709 CVE-2010-3436
Created:November 1, 2010 Updated:April 15, 2011
Description: From the Mandriva advisory:

Stack consumption vulnerability in the filter_var function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3, when FILTER_VALIDATE_EMAIL mode is used, allows remote attackers to cause a denial of service (memory consumption and application crash) via a long e-mail address string (CVE-2010-3710).

A NULL pointer dereference was discovered in ZipArchive::getArchiveComment (CVE-2010-3709).

A possible flaw was discovered in open_basedir (CVE-2010-3436).

Alerts:
Gentoo 201110-06 2011-10-10
CentOS CESA-2011:0196 2011-04-14
openSUSE openSUSE-SU-2011:0276-1 2011-04-01
Debian DSA-2195-1 2011-03-19
Red Hat RHSA-2011:0196-01 2011-02-03
Red Hat RHSA-2011:0195-01 2011-02-03
Ubuntu USN-1042-2 2011-01-13
Ubuntu USN-1042-1 2011-01-11
Fedora FEDORA-2010-19011 2010-12-17
Fedora FEDORA-2010-18976 2010-12-17
Fedora FEDORA-2010-19011 2010-12-17
Fedora FEDORA-2010-18976 2010-12-17
Fedora FEDORA-2010-19011 2010-12-17
Fedora FEDORA-2010-18976 2010-12-17
Slackware SSA:2010-357-01 2010-12-24
SUSE SUSE-SR:2010:023 2010-12-08
openSUSE openSUSE-SU-2010:1012-1 2010-12-02
Mandriva MDVSA-2010:218 2010-10-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds