CVE Vulnerabilities

CVE-2009-1271

Published: Apr 08, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp5.2.0 (including)5.2.0 (including)
PhpPhp5.2.1 (including)5.2.1 (including)
PhpPhp5.2.2 (including)5.2.2 (including)
PhpPhp5.2.3 (including)5.2.3 (including)
PhpPhp5.2.4 (including)5.2.4 (including)
PhpPhp5.2.5 (including)5.2.5 (including)
PhpPhp5.2.6 (including)5.2.6 (including)
PhpPhp5.2.7 (including)5.2.7 (including)
PhpPhp5.2.8 (including)5.2.8 (including)
Php-json-extUbuntudapper*
Php-json-extUbuntuupstream*
Php5Ubuntugutsy*
Php5Ubuntuhardy*
Php5Ubuntuintrepid*
Php5Ubuntujaunty*
Php5Ubuntuupstream*

References