CVE-2010-3710

PHP 5.2.x-5.2.14 and 5.3.x-5.3.3 - Denial of Service via Long Email Address in filter_var

Title source: llm
STIX 2.1

Description

Stack consumption vulnerability in the filter_var function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3, when FILTER_VALIDATE_EMAIL mode is used, allows remote attackers to cause a denial of service (memory consumption and application crash) via a long e-mail address string.

References (20)

Core 20
Core References
Vendor Advisory x_refsource_confirm
http://www.php.net/archive/2010.php#id2010-12-10-1
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0077
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052836.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42812
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=133469208622507&w=2
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-0196.html
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:218
Release Notes x_refsource_confirm
http://www.php.net/releases/5_3_4.php
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/43926
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1042-1
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0021
Vendor Advisory x_refsource_confirm
http://www.php.net/ChangeLog-5.php
Release Notes x_refsource_confirm
http://www.php.net/releases/5_2_15.php
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052845.html
Exploit x_refsource_confirm
http://bugs.php.net/bug.php?id=52929
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0020
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43189
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4581

Scores

EPSS 0.0278
EPSS Percentile 86.3%

Details

CWE
CWE-399
Status published
Products (19)
php/php 5.2.0
php/php 5.2.1
php/php 5.2.2
php/php 5.2.3
php/php 5.2.4
php/php 5.2.5
php/php 5.2.6
php/php 5.2.7
php/php 5.2.8
php/php 5.2.9
... and 9 more
Published Oct 25, 2010
Tracked Since Feb 18, 2026