CVE Vulnerabilities

CVE-2009-1271

Published: Apr 08, 2009 | Modified: Oct 03, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

Affected Software

Name Vendor Start Version End Version
Php Php 5.2.0 (including) 5.2.0 (including)
Php Php 5.2.1 (including) 5.2.1 (including)
Php Php 5.2.2 (including) 5.2.2 (including)
Php Php 5.2.3 (including) 5.2.3 (including)
Php Php 5.2.4 (including) 5.2.4 (including)
Php Php 5.2.5 (including) 5.2.5 (including)
Php Php 5.2.6 (including) 5.2.6 (including)
Php Php 5.2.7 (including) 5.2.7 (including)
Php Php 5.2.8 (including) 5.2.8 (including)
Php-json-ext Ubuntu dapper *
Php-json-ext Ubuntu upstream *
Php5 Ubuntu gutsy *
Php5 Ubuntu hardy *
Php5 Ubuntu intrepid *
Php5 Ubuntu jaunty *
Php5 Ubuntu upstream *

References