LWN.net Logo

php5: denial of service

Package(s):php5 CVE #(s):CVE-2012-3450
Created:August 14, 2012 Updated:August 15, 2012
Description: From the CVE entry:

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

Alerts:
Debian DSA-2527-1 2012-08-13
Ubuntu USN-1569-1 2012-09-17
Gentoo 201209-03 2012-09-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds