// For flags

CVE-2013-3735

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Zend Engine in PHP before 5.4.16 RC1, and 5.5.0 before RC2, does not properly determine whether a parser error occurred, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted function definition, as demonstrated by an attack within a shared web-hosting environment. NOTE: the vendor's http://php.net/security-note.php page says "for critical security situations you should be using OS-level security by running multiple web servers each as their own user id.

** EN DISPUTA ** El Zend Engine en PHP anterior a v5.4.16 RC1, y v5.5.0 anterior a RC2, no determina de forma precisa si ocurre un error del analizador sintáctica, lo que permite a atacantes dependiendo del contexto provocar una denegación de servicio (consumo de memoria y caída de la aplicación) a través de una definición de una función manipulada, como se demostró por un ataque en un entorno de alojamiento Web. NOTA: la página http://php.net/security-note.php del distribuidor dice "para situaciones críticas de seguridad debería usar seguridad a nivel de sistema operativo" ejecutando múltipls servidores, cada uno con su propia ID."

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-05-31 CVE Reserved
  • 2013-05-31 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-16 First Exploit
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
<= 5.4.15
Search vendor "Php" for product "Php" and version " <= 5.4.15"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.0
Search vendor "Php" for product "Php" and version "5.4.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.1
Search vendor "Php" for product "Php" and version "5.4.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.2
Search vendor "Php" for product "Php" and version "5.4.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.3
Search vendor "Php" for product "Php" and version "5.4.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.4
Search vendor "Php" for product "Php" and version "5.4.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.5
Search vendor "Php" for product "Php" and version "5.4.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.6
Search vendor "Php" for product "Php" and version "5.4.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.7
Search vendor "Php" for product "Php" and version "5.4.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.8
Search vendor "Php" for product "Php" and version "5.4.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.9
Search vendor "Php" for product "Php" and version "5.4.9"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.10
Search vendor "Php" for product "Php" and version "5.4.10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.11
Search vendor "Php" for product "Php" and version "5.4.11"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.12
Search vendor "Php" for product "Php" and version "5.4.12"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.12
Search vendor "Php" for product "Php" and version "5.4.12"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.12
Search vendor "Php" for product "Php" and version "5.4.12"
rc2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.13
Search vendor "Php" for product "Php" and version "5.4.13"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.13
Search vendor "Php" for product "Php" and version "5.4.13"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.14
Search vendor "Php" for product "Php" and version "5.4.14"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.14
Search vendor "Php" for product "Php" and version "5.4.14"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
<= 5.5.0
Search vendor "Php" for product "Php" and version " <= 5.5.0"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha5
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha6
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta4
Affected