Summary
PHP 5.2 < 5.2.15 suffers multiple vulnerabilities such as crash in the zip extract method, NULL pointer dereference and stack-based buffer overfLow.
Upgrade to PHP version 5.2.15 or later.
Severity
Classification
-
CVE CVE-2010-3436, CVE-2010-3709, CVE-2010-4150, CVE-2010-4697, CVE-2010-4698, CVE-2011-0752 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- AMSI 'file' Parameter Directory Traversal Vulnerability
- Apache Struts CookBook/Examples Multiple Cross-Site Scripting Vulnerabilities
- Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
- AeroMail Cross Site Request Forgery, HTML Injection and Cross Site Scripting Vulnerabilities
- 7Media Web Solutions EduTrac Directory Traversal Vulnerability