CVE-2006-5465
published 2006-11-04CVE-2006-5465: Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars…
PriorityP340high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.70%
94.4th percentile
Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| php | php | <= 5.1.6 | — |
| php | php | <= 5.2.4 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
php htmlentities/htmlspecialchars multibyte sequences
vendor_redhat·2007-11-08·CVSS 7.5
CVE-2007-5898 [HIGH] php htmlentities/htmlspecialchars multibyte sequences
php htmlentities/htmlspecialchars multibyte sequences
The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.
Ubuntu
PHP vulnerability
vendor_ubuntu·2006-11-03·CVSS 7.5
CVE-2006-5465 [HIGH] PHP vulnerability
Title: PHP vulnerability
Summary: PHP vulnerability
Stefan Esser discovered two buffer overflows in the htmlentities() and
htmlspecialchars() functions. By supplying specially crafted input to
PHP applications which process that input with these functions, a
remote attacker could potentially exploit this to execute arbitrary
code with the privileges of the application. (CVE-2006-5465)
This update also fixes bugs in the chdir() and tempnam() functions,
which did not perform proper open_basedir checks. This could allow
local scripts to bypass intended restrictions.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
PHP buffer overflow
vendor_redhat·2006-11-02·CVSS 7.5
CVE-2006-5465 [HIGH] PHP buffer overflow
PHP buffer overflow
Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
GHSA
GHSA-6vhv-2cm2-pw8c: Buffer overflow in PHP before 5
ghsa_unreviewed·2022-05-03
CVE-2006-5465 [HIGH] GHSA-6vhv-2cm2-pw8c: Buffer overflow in PHP before 5
Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions.
GHSA
GHSA-6gp5-g2h4-r5fv: The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2007-5898 [HIGH] GHSA-6gp5-g2h4-r5fv: The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5
The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-5465 PHP buffer overflow
bugzilla·2006-11-06·CVSS 7.5
CVE-2006-5465 [HIGH] CVE-2006-5465 PHP buffer overflow
CVE-2006-5465 PHP buffer overflow
+++ This bug was initially created as a clone of Bug #213543 +++
Stefan Esser told vendor-sec about a buffer overflow in PHP's
htmlentities/htmlspecialchars internal routines. These flaws are triggered when
handling utf-8 data. The danger in this flaw is that these functions are
usually passed user input.
The patch for this issue can be found here:
http://cvs.php.net/viewvc.cgi/php-src/ext/standard/html.c?r1=1.111.2.2.2.2&r2=1.111.2.2.2.3
-- Additional comment from [email protected] on 2006-11-02 13:45 EST --
This issue is public:
http://secunia.com/advisories/22653/
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more informat
Bugzilla
CVE-2006-5465 PHP buffer overflow
bugzilla·2006-11-02·CVSS 7.5
CVE-2006-5465 [HIGH] CVE-2006-5465 PHP buffer overflow
CVE-2006-5465 PHP buffer overflow
+++ This bug was initially created as a clone of Bug #213543 +++
Stefan Esser told vendor-sec about a buffer overflow in PHP's
htmlentities/htmlspecialchars internal routines. These flaws are triggered when
handling utf-8 data. The danger in this flaw is that these functions are
usually passed user input.
The patch for this issue can be found here:
http://cvs.php.net/viewvc.cgi/php-src/ext/standard/html.c?r1=1.111.2.2.2.2&r2=1.111.2.2.2.3
Discussion:
This issue is public:
http://secunia.com/advisories/22653/
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please fo
Bugzilla
CVE-2006-5465 PHP buffer overflow
bugzilla·2006-11-02·CVSS 7.5
CVE-2006-5465 [HIGH] CVE-2006-5465 PHP buffer overflow
CVE-2006-5465 PHP buffer overflow
+++ This bug was initially created as a clone of Bug #213543 +++
Stefan Esser told vendor-sec about a buffer overflow in PHP's
htmlentities/htmlspecialchars internal routines. These flaws are triggered when
handling utf-8 data. The danger in this flaw is that these functions are
usually passed user input.
The patch for this issue can be found here:
http://cvs.php.net/viewvc.cgi/php-src/ext/standard/html.c?r1=1.111.2.2.2.2&r2=1.111.2.2.2.3
-- Additional comment from [email protected] on 2006-11-02 13:39 EST --
This issue is public:
http://secunia.com/advisories/22653/
This issue should also affect FC5
Discussion:
php-5.1.6-1.2 has been pushed for fc5, which should resolve this issue. If these problems are still present in this version, then please
Bugzilla
CVE-2006-5465 PHP buffer overflow
bugzilla·2006-11-01·CVSS 7.5
CVE-2006-5465 [HIGH] CVE-2006-5465 PHP buffer overflow
CVE-2006-5465 PHP buffer overflow
Stefan Esser told vendor-sec about a buffer overflow in PHP's
htmlentities/htmlspecialchars internal routines. These flaws are triggered when
handling utf-8 data. The danger in this flaw is that these functions are
usually passed user input.
The patch for this issue can be found here:
http://cvs.php.net/viewvc.cgi/php-src/ext/standard/html.c?r1=1.111.2.2.2.2&r2=1.111.2.2.2.3
This issue also affects RHEL2.1 and RHEL3
Discussion:
This issue is public:
http://secunia.com/advisories/22653/
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. Yo
ftp://patches.sgi.com/support/free/security/advisories/20061101-01-Phttp://docs.info.apple.com/article.html?artnum=304829http://issues.rpath.com/browse/RPL-761http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0736.htmlhttp://secunia.com/advisories/22653http://secunia.com/advisories/22685http://secunia.com/advisories/22688http://secunia.com/advisories/22693http://secunia.com/advisories/22713http://secunia.com/advisories/22753http://secunia.com/advisories/22759http://secunia.com/advisories/22779http://secunia.com/advisories/22881http://secunia.com/advisories/22929http://secunia.com/advisories/23139http://secunia.com/advisories/23155http://secunia.com/advisories/23247http://secunia.com/advisories/24606http://secunia.com/advisories/25047http://security.gentoo.org/glsa/glsa-200703-21.xmlhttp://securitytracker.com/id?1017152http://securitytracker.com/id?1017296http://support.avaya.com/elmodocs2/security/ASA-2006-245.htmhttp://www.cisco.com/en/US/products/products_security_response09186a008082c4fe.htmlhttp://www.cisco.com/warp/public/707/cisco-air-20070425-http.shtmlhttp://www.debian.org/security/2006/dsa-1206http://www.hardened-php.net/advisory_132006.138.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:196http://www.novell.com/linux/security/advisories/2006_67_php.htmlhttp://www.openpkg.com/security/advisories/OpenPKG-SA-2006.028.htmlhttp://www.php.net/releases/5_2_0.phphttp://www.redhat.com/support/errata/RHSA-2006-0730.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0731.htmlhttp://www.securityfocus.com/archive/1/450431/100/0/threadedhttp://www.securityfocus.com/archive/1/451098/100/0/threadedhttp://www.securityfocus.com/archive/1/453024/100/0/threadedhttp://www.securityfocus.com/bid/20879http://www.trustix.org/errata/2006/0061/http://www.turbolinux.com/security/2006/TLSA-2006-38.txthttp://www.ubuntu.com/usn/usn-375-1http://www.us-cert.gov/cas/techalerts/TA06-333A.htmlhttp://www.vupen.com/english/advisories/2006/4317http://www.vupen.com/english/advisories/2006/4749http://www.vupen.com/english/advisories/2006/4750http://www.vupen.com/english/advisories/2007/1546https://exchange.xforce.ibmcloud.com/vulnerabilities/29971https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10240ftp://patches.sgi.com/support/free/security/advisories/20061101-01-Phttp://docs.info.apple.com/article.html?artnum=304829http://issues.rpath.com/browse/RPL-761http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0736.htmlhttp://secunia.com/advisories/22653http://secunia.com/advisories/22685http://secunia.com/advisories/22688http://secunia.com/advisories/22693http://secunia.com/advisories/22713http://secunia.com/advisories/22753http://secunia.com/advisories/22759http://secunia.com/advisories/22779http://secunia.com/advisories/22881http://secunia.com/advisories/22929http://secunia.com/advisories/23139http://secunia.com/advisories/23155http://secunia.com/advisories/23247http://secunia.com/advisories/24606http://secunia.com/advisories/25047http://security.gentoo.org/glsa/glsa-200703-21.xmlhttp://securitytracker.com/id?1017152http://securitytracker.com/id?1017296http://support.avaya.com/elmodocs2/security/ASA-2006-245.htmhttp://www.cisco.com/en/US/products/products_security_response09186a008082c4fe.htmlhttp://www.cisco.com/warp/public/707/cisco-air-20070425-http.shtmlhttp://www.debian.org/security/2006/dsa-1206http://www.hardened-php.net/advisory_132006.138.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:196http://www.novell.com/linux/security/advisories/2006_67_php.htmlhttp://www.openpkg.com/security/advisories/OpenPKG-SA-2006.028.htmlhttp://www.php.net/releases/5_2_0.phphttp://www.redhat.com/support/errata/RHSA-2006-0730.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0731.htmlhttp://www.securityfocus.com/archive/1/450431/100/0/threadedhttp://www.securityfocus.com/archive/1/451098/100/0/threadedhttp://www.securityfocus.com/archive/1/453024/100/0/threadedhttp://www.securityfocus.com/bid/20879http://www.trustix.org/errata/2006/0061/http://www.turbolinux.com/security/2006/TLSA-2006-38.txthttp://www.ubuntu.com/usn/usn-375-1http://www.us-cert.gov/cas/techalerts/TA06-333A.htmlhttp://www.vupen.com/english/advisories/2006/4317http://www.vupen.com/english/advisories/2006/4749http://www.vupen.com/english/advisories/2006/4750http://www.vupen.com/english/advisories/2007/1546https://exchange.xforce.ibmcloud.com/vulnerabilities/29971https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10240
2006-11-04
Published