MDVSA-2010:009 -- Mandriva phpID: oval:org.secpod.oval:def:300208 | Date: (C)2012-01-07 (M)2024-02-19 |
Class: PATCH | Family: unix |
A vulnerability has been found and corrected in php: The htmlspecialchars function in PHP before 5.2.12 does not properly handle overlong UTF-8 sequences, invalid Shift_JIS sequences, and invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting attacks by placing a crafted byte sequence before a special character . The updated packages have been patched to correct this issue.
Platform: |
Mandriva Linux 2010.0 |
Mandriva Linux 2009.1 |