Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-5557
StatusCandidate
DescriptionHeap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not properly handled during Unicode conversion, related to the (1) mb_convert_encoding, (2) mb_check_encoding, (3) mb_convert_variables, and (4) mb_parse_str functions.
PhaseAssigned (15.12.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5557
ReferencesBID : 32948
 BUGTRAQ : 20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl
 CONFIRM : http://bugs.php.net/bug.php?id=45722
 CONFIRM : http://cvs.php.net/viewvc.cgi/php-src/ext/mbstring...
 CONFIRM : http://wiki.rpath.com/Advisories:rPSA-2009-0035
 CONFIRM : http://www.php.net/ChangeLog-5.php#5.2.7
 FULLDISC : 20081221 CVE-2008-5557 - PHP mbstring buffer overflow
 MANDRIVA : MDVSA-2009:045
 SECTRACK : 1021482
 SUSE : SUSE-SR:2009:004
 XF : php-multibyte-bo(47525)
SecurityVulns:PHP 4 multiple function buffer overflows

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod
 



Rating@Mail.ru