Computer Security
[EN] securityvulns.ru
no-pyccku



PHP zend_hash_init function infinite loop
updated since 22.02.2007
Published:02.03.2007
Source:CVE
SecurityVulns ID:7279
Type:remote
Level:5/10
Description:Infinite loop on 64-bit platforms.
Affected:PHP : PHP 4.4
 PHP : PHP 5.2
CVE:CVE-2007-1285 (The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.)
 CVE-2007-0988 (The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-bit arguments to be used after the check for a negative value, as demonstrated by an "a:2147483649:{" argument.)
Original documentdocumentPHP-SECURITY, MOPB-05-2007:PHP unserialize() 64 bit Array Creation Denial of Service Vulnerability (02.03.2007)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server