Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:800373
Category:Denial of Service
Title:PHP < 4.4.5, 5.1.x < 5.1.7, 5.2.x < 5.2.6 DoS Vulnerability
Summary:PHP is prone to a denial of service (DoS) vulnerability.
Description:Summary:
PHP is prone to a denial of service (DoS) vulnerability.

Vulnerability Insight:
An error occurs in the 'mbstring.func_overload' setting in
.htaccess file. It can be exploited via modifying behavior of other sites hosted on the same web
server which causes this setting to be applied to other virtual hosts on the same server.

Vulnerability Impact:
Successful exploitation will let the local attackers to crash
an affected web server.

Affected Software/OS:
PHP version 4.4.4 and prior, 5.1.x through 5.1.6 and 5.2.x
through 5.2.5.

Solution:
Update to version 4.4.5, 5.1.7, 5.2.6 or later.

CVSS Score:
2.1

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-0754
Debian Security Information: DSA-1789 (Google Search)
http://www.debian.org/security/2009/dsa-1789
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html
http://www.openwall.com/lists/oss-security/2009/01/30/1
http://www.openwall.com/lists/oss-security/2009/02/03/3
http://www.openwall.com/lists/oss-security/2009/02/25/3
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11035
http://www.redhat.com/support/errata/RHSA-2009-0350.html
http://www.securitytracker.com/id?1021979
http://secunia.com/advisories/34642
http://secunia.com/advisories/34830
http://secunia.com/advisories/35003
http://secunia.com/advisories/35007
http://secunia.com/advisories/35306
SuSE Security Announcement: SUSE-SR:2009:008 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html
https://usn.ubuntu.com/761-1/
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.