CVE Vulnerabilities

CVE-2010-1861

Published: May 07, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
3.7 N/A
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to write to arbitrary memory addresses by using an objects __sleep function to interrupt an internal call to the shm_put_var function, which triggers access of a freed resource.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp5.2.0 (including)5.2.0 (including)
PhpPhp5.2.1 (including)5.2.1 (including)
PhpPhp5.2.2 (including)5.2.2 (including)
PhpPhp5.2.3 (including)5.2.3 (including)
PhpPhp5.2.4 (including)5.2.4 (including)
PhpPhp5.2.5 (including)5.2.5 (including)
PhpPhp5.2.6 (including)5.2.6 (including)
PhpPhp5.2.8 (including)5.2.8 (including)
PhpPhp5.2.9 (including)5.2.9 (including)
PhpPhp5.2.10 (including)5.2.10 (including)
PhpPhp5.2.11 (including)5.2.11 (including)
PhpPhp5.2.12 (including)5.2.12 (including)
PhpPhp5.2.13 (including)5.2.13 (including)
Php5Ubuntudapper*
Php5Ubuntuhardy*
Php5Ubuntujaunty*
Php5Ubuntukarmic*
Php5Ubuntulucid*
Php5Ubuntuupstream*

References