Description
The zend_alter_ini_entry function in PHP before 5.2.4 does not properly handle an interruption to the flow of execution triggered by a memory_limit violation, which has unknown impact and attack vectors.
Remediation
References
Related Vulnerabilities
MySQL CVE-2023-22112 Vulnerability (CVE-2023-22112)
Internet Information Services Other Vulnerability (CVE-1999-1537)
WebLogic CVE-2022-21347 Vulnerability (CVE-2022-21347)
Oracle HTTP Server Improper Encoding or Escaping of Output Vulnerability (CVE-2022-25235)
WordPress Plugin TheCartPress eCommerce Shopping Cart Order Information Security Bypass (1.1.9.2)