bugs.php.netConfirmation
http://bugs.php.net/bug.php?id=54193 CVE-2011-1092
PHP 5.3.6 - 'shmop_read()' Integer Overflow Denial of Service
Record summary
CVE-2011-1092 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHP 5.3.6 - 'shmop_read()' Integer Overflow Denial of ServiceExploitDB exploitby Jose Carlos NorteNot analyzed1 file
References
Showing 12 of 19APPLE-SA-2011-10-12-3Vendor advisory
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html HPSBOV02763Vendor advisory
http://marc.info/?l=bugtraq&m=133469208622507&w=2 8130Third-party advisory
http://securityreason.com/securityalert/8130 support.apple.comConfirmation
http://support.apple.com/kb/HT5002 svn.php.netConfirmation
http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/shmop/shmop.c?r1=306939&r2=309018&pathrev=309018 16966exploit
http://www.exploit-db.com/exploits/16966 MDVSA-2011:052Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2011:052 MDVSA-2011:053Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2011:053 [oss-security] 20110308 Re: CVE request, php's shmmailing list
http://www.openwall.com/lists/oss-security/2011/03/08/11 [oss-security] 20110308 CVE request, php's shmmailing list
http://www.openwall.com/lists/oss-security/2011/03/08/9 php.netConfirmation
http://www.php.net/ChangeLog-5.php