[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-1915Date: (C)2010-05-12   (M)2024-02-22


The preg_quote function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature, modification of ZVALs whose values are not updated in the associated local variables, and access of previously-freed memory.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SUSE-SR:2010:017
SUSE-SR:2010:018
http://www.php-security.org/2010/05/09/mops-2010-017-php-preg_quote-interruption-information-leak-vulnerability/index.html
php-pregquote-information-disclosure(58586)

CPE    16
cpe:/a:php:php:5.2.11
cpe:/a:php:php:5.2.10
cpe:/a:php:php:5.3.2
cpe:/a:php:php:5.2.3
...
CWE    1
CWE-200
OVAL    6
oval:org.secpod.oval:def:101060
oval:org.secpod.oval:def:100434
oval:org.secpod.oval:def:100345
oval:org.secpod.oval:def:100796
...

© SecPod Technologies