Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.800373
Category:Denial of Service
Title:PHP 'mbstring.func_overload' DoS Vulnerability
Summary:PHP is prone to a denial of service vulnerability.
Description:Summary:
PHP is prone to a denial of service vulnerability.

Vulnerability Insight:
This bug is due to an error in 'mbstring.func_overload' setting in .htaccess
file. It can be exploited via modifying behavior of other sites hosted on
the same web server which causes this setting to be applied to other virtual
hosts on the same server.

Vulnerability Impact:
Successful exploitation will let the local attackers to crash an affected web server.

Affected Software/OS:
PHP version 4.4.4 and prior

PHP 5.1.x to 5.1.6

PHP 5.2.x to 5.2.5

Solution:
Update to version 4.4.5, 5.1.7, 5.2.6 or later.

CVSS Score:
2.1

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: BugTraq ID: 33542
Common Vulnerability Exposure (CVE) ID: CVE-2009-0754
Debian Security Information: DSA-1789 (Google Search)
http://www.debian.org/security/2009/dsa-1789
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html
http://www.openwall.com/lists/oss-security/2009/01/30/1
http://www.openwall.com/lists/oss-security/2009/02/03/3
http://www.openwall.com/lists/oss-security/2009/02/25/3
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11035
http://www.redhat.com/support/errata/RHSA-2009-0350.html
http://www.securitytracker.com/id?1021979
http://secunia.com/advisories/34642
http://secunia.com/advisories/34830
http://secunia.com/advisories/35003
http://secunia.com/advisories/35007
http://secunia.com/advisories/35306
SuSE Security Announcement: SUSE-SR:2009:008 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html
https://usn.ubuntu.com/761-1/
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.