bugs.debian.orgConfirmation
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=573573 CVE-2010-0397
PHP 5.3.2 'xmlrpc' Extension - Multiple Remote Denial of Service Vulnerabilities
Record summary
CVE-2010-0397 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHP 5.3.2 'xmlrpc' Extension - Multiple Remote Denial of Service VulnerabilitiesExploitDB exploitby Auke van SlootenNot analyzed1 file
References
Showing 12 of 16APPLE-SA-2010-08-24-1Vendor advisory
http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html APPLE-SA-2010-11-10-1Vendor advisory
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html SUSE-SR:2010:012Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html SUSE-SR:2010:013Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html SUSE-SR:2010:017Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html 42410Third-party advisory
http://secunia.com/advisories/42410 support.apple.comConfirmation
http://support.apple.com/kb/HT4312 support.apple.comConfirmation
http://support.apple.com/kb/HT4435 MDVSA-2010:068Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2010:068 [oss-security] 20100312 CVE-2010-0397: NULL pointer dereference in PHP's xmlrpc extensionmailing list
http://www.openwall.com/lists/oss-security/2010/03/12/5 RHSA-2010:0919Vendor advisory
http://www.redhat.com/support/errata/RHSA-2010-0919.html