Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.803729
Kategorie:Buffer overflow
Titel:PHP XML Handling Heap Buffer Overflow Vulnerability (Jul 2013) - Windows
Zusammenfassung:PHP is prone to a heap based buffer overflow vulnerability.
Beschreibung:Summary:
PHP is prone to a heap based buffer overflow vulnerability.

Vulnerability Insight:
The flaw is triggered as user-supplied input is not properly validated when
handling malformed XML input.

Vulnerability Impact:
Successful exploitation will allow attackers to cause a heap-based buffer
overflow, resulting in a denial of service or potentially allowing the
execution of arbitrary code.

Affected Software/OS:
PHP version prior to 5.3.27

Solution:
Update to PHP version 5.3.27 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2013-4113
Debian Security Information: DSA-2723 (Google Search)
http://www.debian.org/security/2013/dsa-2723
RedHat Security Advisories: RHSA-2013:1049
http://rhn.redhat.com/errata/RHSA-2013-1049.html
RedHat Security Advisories: RHSA-2013:1050
http://rhn.redhat.com/errata/RHSA-2013-1050.html
RedHat Security Advisories: RHSA-2013:1061
http://rhn.redhat.com/errata/RHSA-2013-1061.html
RedHat Security Advisories: RHSA-2013:1062
http://rhn.redhat.com/errata/RHSA-2013-1062.html
RedHat Security Advisories: RHSA-2013:1063
http://rhn.redhat.com/errata/RHSA-2013-1063.html
http://secunia.com/advisories/54071
http://secunia.com/advisories/54104
http://secunia.com/advisories/54163
http://secunia.com/advisories/54165
SuSE Security Announcement: SUSE-SU-2013:1285 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00034.html
SuSE Security Announcement: SUSE-SU-2013:1315 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.html
SuSE Security Announcement: SUSE-SU-2013:1316 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00007.html
http://www.ubuntu.com/usn/USN-1905-1
CopyrightCopyright (C) 2013 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.