Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-3450
Description:pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2012.1033.1   1.3.6.1.4.1.25623.1.0.71823   1.3.6.1.4.1.25623.1.0.802670  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-3450
20120610 [php<=5.4.3] Parsing Bug in PHP PDO prepared statements may lead to access violation
http://seclists.org/bugtraq/2012/Jun/60
DSA-2527
http://www.debian.org/security/2012/dsa-2527
MDVSA-2012:108
http://www.mandriva.com/security/advisories?name=MDVSA-2012:108
SUSE-SU-2012:1033
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00021.html
USN-1569-1
http://www.ubuntu.com/usn/USN-1569-1
[oss-security] 20120802 CVE Request: php5 pdo array overread/crash
http://www.openwall.com/lists/oss-security/2012/08/02/3
[oss-security] 20120802 Re: CVE Request: php5 pdo array overread/crash
http://www.openwall.com/lists/oss-security/2012/08/02/7
http://www.php.net/ChangeLog-5.php
http://www.php.net/ChangeLog-5.php
https://bugs.php.net/bug.php?id=61755
https://bugs.php.net/bug.php?id=61755
https://bugzilla.novell.com/show_bug.cgi?id=769785
https://bugzilla.novell.com/show_bug.cgi?id=769785




© 1998-2025 E-Soft Inc. All rights reserved.