PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | 5.2.1 (including) | 5.2.1 (including) |
Php5 | Ubuntu | feisty | * |
Php5 | Ubuntu | upstream | * |