Back

HIGH

php: Buffer overflow in com_print_typeinfo() by parsing certain variant types

Published May 21, 2012

Description

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.

Affected products

Remediation

Red Hat statement

Not vulnerable. This flaw is specific to PHP instances, running on Microsoft Windows platform.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 21, 2012
Updated Aug 6, 2024
Reserved Apr 19, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date May 19, 2012