Description
The Zend Engine in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information by interrupting the handler for the (1) ZEND_BW_XOR opcode (shift_left_function), (2) ZEND_SL opcode (bitwise_xor_function), or (3) ZEND_SR opcode (shift_right_function), related to the convert_to_long_base function.
Remediation
References
Related Vulnerabilities
Chamilo Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-1999019)
WordPress Plugin Custom Website Data Cross-Site Scripting (2.2)
Oracle Application Server Other Vulnerability (CVE-2004-1774)
Drupal Core 7.x Denial of Service (7.0 - 7.19)
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2011-4317)