php: information disclosure/arbitrary code execution
Package(s): | php |
CVE #(s): | CVE-2010-2950
|
Created: | June 27, 2012 |
Updated: | July 2, 2012 |
Description: |
From the Red Hat advisory:
A format string flaw was found in the way the PHP phar extension processed
certain PHAR files. A remote attacker could provide a specially-crafted
PHAR file, which once processed in a PHP application using the phar
extension, could lead to information disclosure and possibly arbitrary code
execution via a crafted phar:// URI. |
Alerts: |
|