[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99602

 
 

909

 
 

80170

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2011-3268

Date: (C)2011-08-25   (M)2017-12-01 


Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

CVSS Score: 10.0Access Vector: NETWORK
Exploit Score: 10.0Access Complexity: LOW
Impact Score: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE





Reference:
BID-49241
OSVDB-74738
APPLE-SA-2012-02-01-1
IAVM:2012-B-0056
MDVSA-2011:165
http://support.apple.com/kb/HT5130
http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/standard/php_crypt_r.c?r1=311300&r2=311390&pathrev=315218
http://www.php.net/ChangeLog-5.php#5.3.7
http://www.php.net/archive/2011.php#id2011-08-18-1
php-crypt-bo(69427)

CPE    105
cpe:/a:php:php:3.0
cpe:/a:php:php:5.1.0
cpe:/a:php:php:4.3.4
cpe:/a:php:php:4.3.3
...
CWE    1
CWE-119
OVAL    5
oval:org.secpod.oval:def:301125
oval:org.secpod.oval:def:2232
oval:org.secpod.oval:def:3903
oval:org.secpod.oval:def:3930
...

© 2013 SecPod Technologies