The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | 5.3.9 (including) | 5.3.9 (including) |
Red Hat Enterprise Linux 4 | RedHat | php-0:4.3.9-3.36 | * |
Red Hat Enterprise Linux 5 | RedHat | php53-0:5.3.3-1.el5_7.6 | * |
Red Hat Enterprise Linux 5 | RedHat | php-0:5.1.6-27.el5_7.5 | * |
Red Hat Enterprise Linux 6 | RedHat | php-0:5.3.3-3.el6_2.6 | * |
Php5 | Ubuntu | hardy | * |
Php5 | Ubuntu | lucid | * |
Php5 | Ubuntu | maverick | * |
Php5 | Ubuntu | natty | * |
Php5 | Ubuntu | oneiric | * |
Php5 | Ubuntu | upstream | * |