CVE Vulnerabilities

CVE-2012-3450

Published: Aug 06, 2012 | Modified: Apr 19, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V2
6.8 N/A
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

Affected Software

Name Vendor Start Version End Version
Php Php * 5.3.13 (including)
Php Php 5.3.0 (including) 5.3.0 (including)
Php Php 5.3.1 (including) 5.3.1 (including)
Php Php 5.3.2 (including) 5.3.2 (including)
Php Php 5.3.3 (including) 5.3.3 (including)
Php Php 5.3.4 (including) 5.3.4 (including)
Php Php 5.3.5 (including) 5.3.5 (including)
Php Php 5.3.6 (including) 5.3.6 (including)
Php Php 5.3.7 (including) 5.3.7 (including)
Php Php 5.3.8 (including) 5.3.8 (including)
Php Php 5.3.9 (including) 5.3.9 (including)
Php Php 5.3.10 (including) 5.3.10 (including)
Php Php 5.3.11 (including) 5.3.11 (including)
Php Php 5.3.12 (including) 5.3.12 (including)
Php Php 5.4.0 (including) 5.4.0 (including)
Php Php 5.4.1 (including) 5.4.1 (including)
Php Php 5.4.2 (including) 5.4.2 (including)
Php Php 5.4.3 (including) 5.4.3 (including)
Php5 Ubuntu hardy *
Php5 Ubuntu lucid *
Php5 Ubuntu natty *
Php5 Ubuntu oneiric *
Php5 Ubuntu precise *

References