Back

MEDIUM

php: NULL pointer dereference in XML-RPC extension

Published Mar 16, 2010

Description

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

Affected products

Remediation

Red Hat statement

This issue was addressed in the php packages as shipped with Red Hat Enterprise Linux 4 and 5 via: https://rhn.redhat.com/errata/RHSA-2010-0919.html

Metrics

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 16, 2010
Updated Aug 7, 2024
Reserved Jan 27, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Mar 12, 2010