Executive Summary

Summary
Titlephp5 security update
Informations
NameDSA-2403First vendor Publication2012-02-02
VendorDebianLast vendor Modification2012-02-06
Severity (Vendor) N/ARevision2

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score7.5Attack RangeNetwork
Cvss Impact Score6.4Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.

This update adds packages for the oldstable distribution, which were missing from the original advisory. The problem has been fixed in version 5.2.6.dfsg.1-1+lenny16, installed into the security archive on 3 Feb 2012.

For the stable distribution (squeeze), this problem has been fixed in version 5.3.3-7+squeeze7.

For the unstable distribution (sid), this problem has been fixed in version 5.3.10-1.

We recommend that you upgrade your php5 packages.

Original Source

Url : http://www.debian.org/security/2012/dsa-2403

CWE : Common Weakness Enumeration

idName
CWE-399Resource Management Errors

CPE : Common Platform Enumeration

TypeDescriptionCount
Application1