The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | 5.3.1 (including) | 5.3.1 (including) |
Red Hat Enterprise Linux 4 | RedHat | php-0:4.3.9-3.31 | * |
Red Hat Enterprise Linux 5 | RedHat | php-0:5.1.6-27.el5_5.3 | * |
Php5 | Ubuntu | dapper | * |
Php5 | Ubuntu | hardy | * |
Php5 | Ubuntu | intrepid | * |
Php5 | Ubuntu | jaunty | * |
Php5 | Ubuntu | karmic | * |
Php5 | Ubuntu | upstream | * |