CVE-2010-2531
published 2010-08-20CVE-2010-2531: The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
5.00%
91.3th percentile
The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the application to exceed limits for memory, execution time, or recursion.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| php | php | >= 5.2.0 < 5.2.14 | 5.2.14 |
| php | php | >= 5.3.0 < 5.3.3 | 5.3.3 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu5.0MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2010-09-20·CVSS 5.0
CVE-2010-0397 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc
requests. An attacker could exploit this issue to cause the PHP server to
crash, resulting in a denial of service. This issue only affected Ubuntu
6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2010-0397)
It was discovered that the pseudorandom number generator in PHP did not
provide the expected entropy. An attacker could exploit this issue to
predict values that were intended to be random, such as session cookies.
This issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 9.04 and 9.10.
(CVE-2010-1128)
It was discovered that PHP did not properly handle directory pathnames that
lacked a trailing slash character. An attacker could exploit this issue to
bypass safe_mode restrictions. This issue only affe
Red Hat
php: information leak vulnerability in var_export()
vendor_redhat·2010-07-09·CVSS 4.3
CVE-2010-2531 [MEDIUM] php: information leak vulnerability in var_export()
php: information leak vulnerability in var_export()
The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the application to exceed limits for memory, execution time, or recursion.
Statement: This issue is not planned to be fixed in Red Hat Enterprise Linux 3 due to this product being in Production 3 of its maintenance life-cycle, where only qualified security errata of important and critical impact are addressed.
For further information about the Errata Support Policy, visit:
http://www.redhat.com/security/updates/errata
Package: php (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-cpj2-grx5-hpg2: The var_export function in PHP 5
ghsa_unreviewed·2022-05-17
CVE-2010-2531 [MEDIUM] CWE-200 GHSA-cpj2-grx5-hpg2: The var_export function in PHP 5
The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the application to exceed limits for memory, execution time, or recursion.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.htmlhttp://marc.info/?l=bugtraq&m=130331363227777&w=2http://marc.info/?l=bugtraq&m=133469208622507&w=2http://secunia.com/advisories/42410http://support.apple.com/kb/HT4312http://support.apple.com/kb/HT4435http://svn.php.net/viewvc/php/php-src/trunk/ext/standard/tests/general_functions/var_export_error2.phpt?view=log&pathrev=301143http://www.debian.org/security/2011/dsa-2266http://www.openwall.com/lists/oss-security/2010/07/13/1http://www.openwall.com/lists/oss-security/2010/07/16/3http://www.php.net/archive/2010.php#id2010-07-22-1http://www.php.net/archive/2010.php#id2010-07-22-2http://www.redhat.com/support/errata/RHSA-2010-0919.htmlhttp://www.vupen.com/english/advisories/2010/3081https://bugzilla.redhat.com/show_bug.cgi?id=617673http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.htmlhttp://marc.info/?l=bugtraq&m=130331363227777&w=2http://marc.info/?l=bugtraq&m=133469208622507&w=2http://secunia.com/advisories/42410http://support.apple.com/kb/HT4312http://support.apple.com/kb/HT4435http://svn.php.net/viewvc/php/php-src/trunk/ext/standard/tests/general_functions/var_export_error2.phpt?view=log&pathrev=301143http://www.debian.org/security/2011/dsa-2266http://www.openwall.com/lists/oss-security/2010/07/13/1http://www.openwall.com/lists/oss-security/2010/07/16/3http://www.php.net/archive/2010.php#id2010-07-22-1http://www.php.net/archive/2010.php#id2010-07-22-2http://www.redhat.com/support/errata/RHSA-2010-0919.htmlhttp://www.vupen.com/english/advisories/2010/3081https://bugzilla.redhat.com/show_bug.cgi?id=617673
2010-08-20
Published