[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-2688Date: (C)2012-07-20   (M)2024-03-21


Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1027287
BID-54638
SECUNIA-55078
APPLE-SA-2012-09-19-2
DSA-2527
MDVSA-2012:108
RHSA-2013:1307
SUSE-SU-2012:1033
SUSE-SU-2012:1034
USN-1569-1
http://support.apple.com/kb/HT5501
http://www.php.net/ChangeLog-5.php
openSUSE-SU-2012:0976
php-phpstreamscandir-unspecified(77155)

CPE    122
cpe:/a:php:php:5.0.0:rc3
cpe:/a:php:php:3.0
cpe:/a:php:php:5.0.0:rc2
cpe:/a:php:php:5.0.0:rc1
...
OVAL    22
oval:org.secpod.oval:def:104031
oval:org.secpod.oval:def:104030
oval:org.secpod.oval:def:10717
oval:org.secpod.oval:def:205810
...

© SecPod Technologies