Back

MEDIUM

php: crash when unserializing serialized PDORow object

Published Feb 14, 2012

Description

The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this flaw to be a security issue. The bug can only be triggered by the PHP script author, which does not cross trust boundary.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 14, 2012
Updated Aug 6, 2024
Reserved Jan 19, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Jan 11, 2012