LWN.net Logo

php: information disclosure/arbitrary code execution

Package(s):php CVE #(s):CVE-2010-2950
Created:June 27, 2012 Updated:July 2, 2012
Description: From the Red Hat advisory:

A format string flaw was found in the way the PHP phar extension processed certain PHAR files. A remote attacker could provide a specially-crafted PHAR file, which once processed in a PHP application using the phar extension, could lead to information disclosure and possibly arbitrary code execution via a crafted phar:// URI.

Alerts:
Red Hat RHSA-2012:1046-01 2012-06-27
Red Hat RHSA-2012:1047-01 2012-06-27
CentOS CESA-2012:1047 2012-06-27
Oracle ELSA-2012-1047 2012-06-28
Oracle ELSA-2012-1046 2012-06-30
Scientific Linux SL-php5-20120705 2012-07-05
Scientific Linux SL-php-20120709 2012-07-09
CentOS CESA-2012:1046 2012-07-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds