|
|
| |
|
| |
php: multiple vulnerabilities
| Package(s): | php |
CVE #(s): | CVE-2010-3710
CVE-2010-3709
CVE-2010-3436
|
| Created: | November 1, 2010 |
Updated: | April 15, 2011 |
| Description: |
From the Mandriva advisory:
Stack consumption vulnerability in the filter_var function in PHP 5.2.x
through 5.2.14 and 5.3.x through 5.3.3, when FILTER_VALIDATE_EMAIL
mode is used, allows remote attackers to cause a denial of service
(memory consumption and application crash) via a long e-mail address
string (CVE-2010-3710).
A NULL pointer dereference was discovered in
ZipArchive::getArchiveComment (CVE-2010-3709).
A possible flaw was discovered in open_basedir (CVE-2010-3436).
|
| Alerts: |
|
( Log in to post comments)
|
|
|