php: Heap-based buffer overflow in quoted_printable_encode()
Published Jun 21, 2013
5.0
MEDIUMCVSS 2.0
EPSS 6.75%
Description
Heap-based buffer overflow in the php_quot_print_encode function in ext/standard/quot_print.c in PHP before 5.3.26 and 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted argument to the quoted_printable_encode function.
Affected products
No data.
Configuration 1
- ≤ 5.3.25
- 1.0
- 2.0
- 2.0b10
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.11
- 3.0.12
- 3.0.13
- 3.0.14
- 3.0.15
- 3.0.16
- 3.0.17
- 3.0.18
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.0.5
- 4.0.6
- 4.0.7
- 4.1.0
- 4.1.1
- 4.1.2
- 4.2.0
- 4.2.1
- 4.2.2
- 4.2.3
- 4.3.0
- 4.3.1
- 4.3.2
- 4.3.3
- 4.3.4
- 4.3.5
- 4.3.6
- 4.3.7
- 4.3.8
- 4.3.9
- 4.3.10
- 4.3.11
- 4.4.0
- 4.4.1
- 4.4.2
- 4.4.3
- 4.4.4
- 4.4.5
- 4.4.6
- 4.4.7
- 4.4.8
- 4.4.9
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.0.4
- 5.0.5
- 5.1.0
- 5.1.1
- 5.1.2
- 5.1.3
- 5.1.4
- 5.1.5
- 5.1.6
- 5.2.0
- 5.2.1
- 5.2.2
- 5.2.3
- 5.2.4
- 5.2.5
- 5.2.6
- 5.2.7
- 5.2.8
- 5.2.9
- 5.2.10
- 5.2.11
- 5.2.12
- 5.2.13
- 5.2.14
- 5.2.15
- 5.2.16
- 5.2.17
- 5.3.0
- 5.3.1
- 5.3.2
- 5.3.3
- 5.3.4
- 5.3.5
- 5.3.6
- 5.3.7
- 5.3.8
- 5.3.9
- 5.3.10
- 5.3.11
- 5.3.12
- 5.3.13
- 5.3.14
- 5.3.15
- 5.3.16
- 5.3.17
- 5.3.18
- 5.3.19
- 5.3.20
- 5.3.21
- 5.3.22
- 5.3.23
- 5.3.24
Configuration 2
- 5.4.0
- 5.4.1
- 5.4.2
- 5.4.3
- 5.4.4
- 5.4.5
- 5.4.6
- 5.4.7
- 5.4.8
- 5.4.9
- 5.4.10
- 5.4.11
- 5.4.12
- 5.4.13
- 5.4.14
- 5.4.15
No data.
Red Hat Enterprise Linux 5
php
Not affected
Red Hat Enterprise Linux 5
php53
Not affected
Red Hat Enterprise Linux 6
php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | php | Not affected | n/a |
| Red Hat Enterprise Linux 5 | php53 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | php | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not Vulnerable. This issue does not affect the version of php as shipped with Red Hat Enterprise Linux 5 and 6. This issue does not affect the version of php53 as shipped with Red Hat Enterprise Linux 5.
References (11)
- http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html vendor-advisoryx_refsource_APPLE
- http://support.apple.com/kb/HT5880 x_refsource_CONFIRM
- http://www.php.net/ChangeLog-5.php x_refsource_CONFIRM
- http://www.securityfocus.com/bid/60411 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1872-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-2110 Vendor Advisory
- https://bugs.php.net/bug.php?id=64879 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=964969 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2080 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-2110
- https://www.cve.org/CVERecord?id=CVE-2013-2110
| Link | Providers | Tags |
|---|---|---|
| http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html | vendor-advisoryx_refsource_APPLE | |
| http://support.apple.com/kb/HT5880 | x_refsource_CONFIRM | |
| http://www.php.net/ChangeLog-5.php | x_refsource_CONFIRM | |
| http://www.securityfocus.com/bid/60411 | vdb-entryx_refsource_BID | |
| http://www.ubuntu.com/usn/USN-1872-1 | vendor-advisoryx_refsource_UBUNTU | |
| https://access.redhat.com/security/cve/CVE-2013-2110 | Vendor Advisory | |
| https://bugs.php.net/bug.php?id=64879 | x_refsource_CONFIRM | |
| https://bugzilla.redhat.com/show_bug.cgi?id=964969 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2080 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-2110 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-2110 |
Change history (0)
No recorded changes yet.