SUSE-SU-2012:1033Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00021.html CVE-2012-3450
PHP 5.4.3 - PDO Memory Access Violation Denial of Service
Record summary
CVE-2012-3450 has a selected CVSS score of 2.6; EIP currently links 1 catalogued exploit.
Description
pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHP 5.4.3 - PDO Memory Access Violation Denial of ServiceExploitDB exploitby 0x721427D8Not analyzed1 file
References
1120120610 [php<=5.4.3] Parsing Bug in PHP PDO prepared statements may lead to access violationmailing list
http://seclists.org/bugtraq/2012/Jun/60 DSA-2527Vendor advisory
http://www.debian.org/security/2012/dsa-2527 MDVSA-2012:108Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2012:108 [oss-security] 20120802 CVE Request: php5 pdo array overread/crashmailing list
http://www.openwall.com/lists/oss-security/2012/08/02/3 [oss-security] 20120802 Re: CVE Request: php5 pdo array overread/crashmailing list
http://www.openwall.com/lists/oss-security/2012/08/02/7 php.netConfirmation
http://www.php.net/ChangeLog-5.php USN-1569-1Vendor advisory
http://www.ubuntu.com/usn/USN-1569-1 bugs.php.netConfirmation
https://bugs.php.net/bug.php?id=61755 bugzilla.novell.comConfirmation
https://bugzilla.novell.com/show_bug.cgi?id=769785 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-3450