Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.103020
Kategorie:Denial of Service
Titel:PHP 'zend_strtod()' Function Floating-Point Value Denial of Service Vulnerability
Zusammenfassung:PHP is prone to a remote denial-of-service vulnerability.
Beschreibung:Summary:
PHP is prone to a remote denial-of-service vulnerability.

Vulnerability Insight:
The vulnerability is due to the Floating-Point Value that exist in zend_strtod function

Vulnerability Impact:
Successful attacks will cause applications written in PHP to hang,
creating a denial-of-service condition.

Affected Software/OS:
PHP 5.3.3 is vulnerable. Other versions may also be affected.

Solution:
Updates are available. Please see the references for more details.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: BugTraq ID: 45668
Common Vulnerability Exposure (CVE) ID: CVE-2010-4645
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
http://www.securityfocus.com/bid/45668
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053355.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053333.html
HPdes Security Advisory: HPSBMU02752
http://marc.info/?l=bugtraq&m=133226187115472&w=2
HPdes Security Advisory: HPSBOV02763
http://marc.info/?l=bugtraq&m=133469208622507&w=2
HPdes Security Advisory: SSRT100802
HPdes Security Advisory: SSRT100826
http://hal.archives-ouvertes.fr/docs/00/28/14/29/PDF/floating-point-article.pdf
http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/Zend/zend_strtod.c?r1=266327&r2=307095&pathrev=307095
http://www.exploringbinary.com/php-hangs-on-numeric-value-2-2250738585072011e-308/
http://www.openwall.com/lists/oss-security/2011/01/05/8
http://www.openwall.com/lists/oss-security/2011/01/05/2
http://www.openwall.com/lists/oss-security/2011/01/06/5
http://www.redhat.com/support/errata/RHSA-2011-0195.html
http://www.redhat.com/support/errata/RHSA-2011-0196.html
http://secunia.com/advisories/42812
http://secunia.com/advisories/42843
http://secunia.com/advisories/43051
http://secunia.com/advisories/43189
http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.484686
http://www.ubuntu.com/usn/USN-1042-1
http://www.vupen.com/english/advisories/2011/0060
http://www.vupen.com/english/advisories/2011/0066
http://www.vupen.com/english/advisories/2011/0077
http://www.vupen.com/english/advisories/2011/0198
XForce ISS Database: php-zendstrtod-dos(64470)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64470
CopyrightCopyright (C) 2011 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.