CVE Vulnerabilities

CVE-2004-0958

Published: Nov 03, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

Affected Software

Name Vendor Start Version End Version
Php Php * 5.0.2 (including)
Red Hat Enterprise Linux 3 RedHat php-0:4.3.2-19.ent *
Php4 Ubuntu dapper *
Php4 Ubuntu edgy *
Php5 Ubuntu dapper *
Php5 Ubuntu devel *
Php5 Ubuntu edgy *
Php5 Ubuntu feisty *

References