MEDIUM
The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable
Published Dec 1, 2009
6.4
MEDIUMCVSS 2.0
EPSS 8.31%
Description
The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable.
Affected products
No data.
OR
- ≤ 5.2.10
- 1.0
- 2.0
- 2.0b10
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.11
- 3.0.12
- 3.0.13
- 3.0.14
- 3.0.15
- 3.0.16
- 3.0.17
- 3.0.18
- 4
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0.0
- 4.0.1
- 4.0.1
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.3
- 4.0.4
- 4.0.4
- 4.0.5
- 4.0.6
- 4.0.7
- 4.0.7
- 4.0.7
- 4.0.7
- 4.0.7
- 4.1.0
- 4.1.1
- 4.1.2
- 4.2
- 4.2.0
- 4.2.1
- 4.2.2
- 4.2.3
- 4.3.0
- 4.3.1
- 4.3.2
- 4.3.3
- 4.3.4
- 4.3.5
- 4.3.6
- 4.3.7
- 4.3.8
- 4.3.9
- 4.3.10
- 4.3.11
- 4.4.0
- 4.4.1
- 4.4.2
- 4.4.3
- 4.4.4
- 4.4.5
- 4.4.6
- 4.4.7
- 4.4.8
- 4.4.9
- 5
- 5.0
- 5.0
- 5.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.0.4
- 5.0.5
- 5.1.0
- 5.1.1
- 5.1.2
- 5.1.3
- 5.1.4
- 5.1.5
- 5.1.6
- 5.2.0
- 5.2.2
- 5.2.4
- 5.2.6
- 5.2.7
- 5.2.8
- 5.2.9
- 5.3.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat does not consider this flaw to be a security issue. The bug can only be triggered by the PHP script author, which does not cross trust boundary.
Weaknesses (0)
No CWE recorded.
References (10)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=540605 x_refsource_CONFIRMPatch
- http://secunia.com/advisories/37482 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securityreason.com/achievement_securityalert/65 third-party-advisoryx_refsource_SREASONRESExploit
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/Zend/zend_ini.c?r1=272370&r2=284156 x_refsource_CONFIRM
- http://www.debian.org/security/2009/dsa-1940 vendor-advisoryx_refsource_DEBIANPatch
- http://www.securityfocus.com/bid/36009 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2009-2626 Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2620 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-2626
- https://www.cve.org/CVERecord?id=CVE-2009-2626
| Link | Providers | Tags |
|---|---|---|
| http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=540605 | x_refsource_CONFIRMPatch | |
| http://secunia.com/advisories/37482 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://securityreason.com/achievement_securityalert/65 | third-party-advisoryx_refsource_SREASONRESExploit | |
| http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/Zend/zend_ini.c?r1=272370&r2=284156 | x_refsource_CONFIRM | |
| http://www.debian.org/security/2009/dsa-1940 | vendor-advisoryx_refsource_DEBIANPatch | |
| http://www.securityfocus.com/bid/36009 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2009-2626 | Vendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2620 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-2626 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-2626 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Dec 1, 2009
Updated Sep 16, 2024
Reserved Jul 28, 2009
Link CVE-2009-2626
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-2620 Assigner certcc
Published Dec 1, 2009
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2009-2620