LOW
PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function
Published Apr 10, 2006
2.1
LOWCVSS 2.0
EPSS 0.86%
Description
PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.
Affected products
Remediation
Red Hat statement
The PHP interpreter does not offer a reliable "sandboxed" security layer (as found in, say, a JVM) in which untrusted scripts can be run; any script run by the PHP interpreter must be trusted with the privileges of the interpreter itself. We therefore do not classify this issue as security-sensitive since no trust boundary is crossed.
Weaknesses (1)
References (16)
- http://securityreason.com/achievement_securityalert/35 third-party-advisoryx_refsource_SREASONRESExploitThird Party Advisory
- http://securityreason.com/securityalert/2312 third-party-advisoryx_refsource_SREASONExploitThird Party Advisory
- http://securityreason.com/securityalert/676 third-party-advisoryx_refsource_SREASONExploitThird Party Advisory
- http://securitytracker.com/id?1015880 vdb-entryx_refsource_SECTRACKExploitThird Party AdvisoryVDB Entry
- http://www.osvdb.org/24485 vdb-entryx_refsource_OSVDBBroken Link
- http://www.php-security.org/MOPB/MOPB-02-2007.html x_refsource_MISCThird Party Advisory
- http://www.securityfocus.com/archive/1/430453/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/430598/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/430742/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/431018/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/22766 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2006/1290 vdb-entryx_refsource_VUPENPermissions RequiredThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2006-1549 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25704 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2006-1549
- https://www.cve.org/CVERecord?id=CVE-2006-1549
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 10, 2006
Updated Aug 7, 2024
Reserved Mar 30, 2006
Link CVE-2006-1549
CISA Vulnrichment
Updated n/a