CVE Vulnerabilities

CVE-2010-1861

Published: May 07, 2010 | Modified: May 10, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
3.7 N/A
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu

The sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to write to arbitrary memory addresses by using an objects __sleep function to interrupt an internal call to the shm_put_var function, which triggers access of a freed resource.

Affected Software

Name Vendor Start Version End Version
Php Php 5.2.0 (including) 5.2.0 (including)
Php Php 5.2.1 (including) 5.2.1 (including)
Php Php 5.2.2 (including) 5.2.2 (including)
Php Php 5.2.3 (including) 5.2.3 (including)
Php Php 5.2.4 (including) 5.2.4 (including)
Php Php 5.2.5 (including) 5.2.5 (including)
Php Php 5.2.6 (including) 5.2.6 (including)
Php Php 5.2.8 (including) 5.2.8 (including)
Php Php 5.2.9 (including) 5.2.9 (including)
Php Php 5.2.10 (including) 5.2.10 (including)
Php Php 5.2.11 (including) 5.2.11 (including)
Php Php 5.2.12 (including) 5.2.12 (including)
Php Php 5.2.13 (including) 5.2.13 (including)

References