Информационная безопасность
[RU] switch to
English Version



CVECVE-2008-5557
СтатусCandidate
ОписаниеHeap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not properly handled during Unicode conversion, related to the (1) mb_convert_encoding, (2) mb_check_encoding, (3) mb_convert_variables, and (4) mb_parse_str functions.
PhaseAssigned (15.12.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5557
ReferencesBID : 32948
 BUGTRAQ : 20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl
 CONFIRM : http://bugs.php.net/bug.php?id=45722
 CONFIRM : http://cvs.php.net/viewvc.cgi/php-src/ext/mbstring...
 CONFIRM : http://wiki.rpath.com/Advisories:rPSA-2009-0035
 CONFIRM : http://www.php.net/ChangeLog-5.php#5.2.7
 FULLDISC : 20081221 CVE-2008-5557 - PHP mbstring buffer overflow
 MANDRIVA : MDVSA-2009:045
 SECTRACK : 1021482
 SUSE : SUSE-SR:2009:004
 XF : php-multibyte-bo(47525)
SecurityVulns:Переполнение буфера во многихфункциях PHP 4
 Многочисленные уязвимости в HP System Management Homepage

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server