4.3

CVE-2010-3709

Exploit

The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.

Data is provided by the National Vulnerability Database (NVD)
PhpPhp Version >= 5.2.0 < 5.2.15
PhpPhp Version >= 5.3.0 < 5.3.4
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version9.10
CanonicalUbuntu Linux Version10.04 SwEdition-
CanonicalUbuntu Linux Version10.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.08% 0.904
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://marc.info/?l=bugtraq&m=133469208622507&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=130331363227777&w=2
Third Party Advisory
Mailing List
http://www.exploit-db.com/exploits/15431
Third Party Advisory
Exploit
VDB Entry
http://www.securityfocus.com/bid/44718
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1024690
Third Party Advisory
VDB Entry