Back

MEDIUM

php: missing $size checks in grapheme_extract()

Published Feb 18, 2011

Description

The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependent attackers to cause a denial of service (crash) via an invalid size argument, which triggers a NULL pointer dereference.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this flaw to be a security issue. The size argument of the grapheme_extract function is unlikely to from an untrusted source unfiltered, therefore the value passed to the function is under the the full control of the script author and no trust boundary is crossed.

Metrics

Weaknesses (0)

No CWE recorded.

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Feb 18, 2011
Updated Aug 6, 2024
Reserved Jan 11, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Feb 17, 2011