CVE-2010-2484

PHP 5.2 - Exposure of Sensitive Information via strrchr Function Interruption

Title source: llm
STIX 2.1

Description

The strrchr function in PHP 5.2 before 5.2.14 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler.

References (8)

Core 8
Core References
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4435
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=133469208622507&w=2
Release Notes x_refsource_confirm
http://www.php.net/releases/5_2_14.php
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=619324
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4312

Scores

EPSS 0.0048
EPSS Percentile 65.2%

Details

CWE
CWE-200
Status published
Products (13)
php/php 5.2.0
php/php 5.2.1
php/php 5.2.2
php/php 5.2.3
php/php 5.2.4
php/php 5.2.5
php/php 5.2.6
php/php 5.2.8
php/php 5.2.9
php/php 5.2.10
... and 3 more
Published Aug 20, 2010
Tracked Since Feb 18, 2026