Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-1657

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2011-1657
Last Modified 03 Feb 2012 10:58:39
Published 25 Aug 2011 10:22:44
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2011-1657

Summary

The (1) ZipArchive::addGlob and (2) ZipArchive::addPattern functions in ext/zip/php_zip.c in PHP 5.3.6 allow context-dependent attackers to cause a denial of service (application crash) via certain flags arguments, as demonstrated by (a) GLOB_ALTDIRFUNC and (b) GLOB_APPEND.

Vulnerable Systems

Application

  • Php 5.3.6


References

MLIST - [oss-security] 20110701 php ZipArchive::addGlob() crashes on invalid flags

CONFIRM - http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/zip/php_zip.c?view=log

CONFIRM - http://svn.php.net/viewvc/?view=revision&revision=310814

CONFIRM - https://bugs.php.net/bug.php?id=54681

XF - php-ziparchiveaddglob-dos(69320)

BID - 49252

BUGTRAQ - 20110819 PHP 5.3.6 ZipArchive invalid use glob(3)

MLIST - [oss-security] 20110701 Re: Re: php ZipArchive::addGlob() crashes on invalid flags

MLIST - [oss-security] 20110701 Re: php ZipArchive::addGlob() crashes on invalid flags

SREASON - 8342

MANDRIVA - MDVSA-2011:165

CONFIRM - http://support.apple.com/kb/HT5130

APPLE - APPLE-SA-2012-02-01-1

Related Patches

Apple 2012-02-01 Mac OS X Server 10.7.3 Update

Apple 2012-02-01 Mac OS X 10.7.3 Update

Apple 2012-02-01 Mac OS X Server 10.7.3 Combo Update

Apple 2012-02-01 Mac OS X 10.7.3 Combo Update

Apple 2012-02-01 Security Update 2012-001 v1.1 Server (Snow Leopard)

Apple 2012-02-01 Security Update 2012-001 v1.1 (Snow Leopard)


Last Updated: 27 May 2016 10:56:26