CVE Vulnerabilities

CVE-2009-0754

Use of Externally-Controlled Format String

Published: Mar 03, 2009 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
2.1 MODERATE
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

Name Vendor Start Version End Version
Php Php 4.4.4 (including) 4.4.4 (including)
Php Php 5.1.6 (including) 5.1.6 (including)
Red Hat Enterprise Linux 3 RedHat php-0:4.3.2-51.ent *
Red Hat Enterprise Linux 4 RedHat php-0:4.3.9-3.22.15 *
Red Hat Enterprise Linux 5 RedHat php-0:5.1.6-23.2.el5_3 *
Php5 Ubuntu dapper *
Php5 Ubuntu devel *
Php5 Ubuntu gutsy *
Php5 Ubuntu hardy *
Php5 Ubuntu intrepid *

Potential Mitigations

References