CVE Vulnerabilities

CVE-2012-3450

Published: Aug 06, 2012 | Modified: Apr 19, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

Affected Software

Name Vendor Start Version End Version
Php Php * 5.3.13 (including)
Php Php 5.3.0 (including) 5.3.0 (including)
Php Php 5.3.1 (including) 5.3.1 (including)
Php Php 5.3.2 (including) 5.3.2 (including)
Php Php 5.3.3 (including) 5.3.3 (including)
Php Php 5.3.4 (including) 5.3.4 (including)
Php Php 5.3.5 (including) 5.3.5 (including)
Php Php 5.3.6 (including) 5.3.6 (including)
Php Php 5.3.7 (including) 5.3.7 (including)
Php Php 5.3.8 (including) 5.3.8 (including)
Php Php 5.3.9 (including) 5.3.9 (including)
Php Php 5.3.10 (including) 5.3.10 (including)
Php Php 5.3.11 (including) 5.3.11 (including)
Php Php 5.3.12 (including) 5.3.12 (including)
Php Php 5.4.0 (including) 5.4.0 (including)
Php Php 5.4.1 (including) 5.4.1 (including)
Php Php 5.4.2 (including) 5.4.2 (including)
Php Php 5.4.3 (including) 5.4.3 (including)

References