cvs.php.netConfirmation
http://cvs.php.net/viewvc.cgi/ZendEngine2/zend_alloc.c?r1=1.161&r2=1.162 CVE-2006-4812
PHP 3 < 5 - ZendEngine ECalloc Integer Overflow
Record summary
CVE-2006-4812 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHP 3 < 5 - ZendEngine ECalloc Integer OverflowExploitDB exploitby anonymousNot analyzed1 file
References
Showing 12 of 27SUSE-SA:2006:059Vendor advisory
http://lists.suse.com/archive/suse-security-announce/2006-Oct/0002.html RHSA-2006:0688Vendor advisory
http://rhn.redhat.com/errata/RHSA-2006-0688.html RHSA-2006:0708Vendor advisory
http://rhn.redhat.com/errata/RHSA-2006-0708.html 22280Third-party advisory
http://secunia.com/advisories/22280 22281Third-party advisory
http://secunia.com/advisories/22281 22300Third-party advisory
http://secunia.com/advisories/22300 22331Third-party advisory
http://secunia.com/advisories/22331 22338Third-party advisory
http://secunia.com/advisories/22338 22533Third-party advisory
http://secunia.com/advisories/22533 22538Third-party advisory
http://secunia.com/advisories/22538 22650Third-party advisory
http://secunia.com/advisories/22650