CVE-2011-1657
Mandriva Linux Security Advisory 2012-071
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The (1) ZipArchive::addGlob and (2) ZipArchive::addPattern functions in ext/zip/php_zip.c in PHP 5.3.6 allow context-dependent attackers to cause a denial of service (application crash) via certain flags arguments, as demonstrated by (a) GLOB_ALTDIRFUNC and (b) GLOB_APPEND.
Las funciones (1) ZipArchive::addGlob y (2) ZipArchive::addPattern en ext/zip/php_zip.c en PHP v5.3.6 permite a atacantes dependientes del contexto provocar una denegación de servicio (caída de la aplicación) a través de ciertos argumentos bandera, como se demostró por (a) GLOB_ALTDIRFUNC y (b) GLOB_APPEND.
Mateusz Kocielski, Marek Kroemeke and Filip Palian discovered that a stack-based buffer overflow existed in the socket_connect function's handling of long pathnames for AF_UNIX sockets. A remote attacker might be able to exploit this to execute arbitrary code; however, the default compiler options for affected releases should reduce the vulnerability to a denial of service. This issue affected Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04. Krzysztof Kotowicz discovered that the PHP post handler function does not properly restrict filenames in multipart/form-data POST requests. This may allow remote attackers to conduct absolute path traversal attacks and possibly create or overwrite arbitrary files. This issue affected Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-04-07 CVE Reserved
- 2011-08-19 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-08-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-399: Resource Management Errors
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/8342 | Third Party Advisory | |
http://support.apple.com/kb/HT5130 | X_refsource_confirm |
|
http://www.openwall.com/lists/oss-security/2011/07/01/7 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2011/07/01/8 | Mailing List |
|
http://www.securityfocus.com/archive/1/519385/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/49252 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/69320 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://securityreason.com/achievement_securityalert/100 | 2024-08-06 | |
https://bugs.php.net/bug.php?id=54681 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html | 2018-10-09 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2011:165 | 2018-10-09 |