CVE-2011-1092
published 2011-03-15CVE-2011-1092: Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive…
PriorityP344high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
17.88%
96.8th percentile
Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function.
Affected
97 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| php | php | <= 5.3.5 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2gm5-2gjp-759h: Integer overflow in ext/shmop/shmop
ghsa_unreviewed·2022-05-14
CVE-2011-1092 [HIGH] GHSA-2gm5-2gjp-759h: Integer overflow in ext/shmop/shmop
Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function.
Ubuntu
PHP Regressions
vendor_ubuntu·2011-05-05·CVSS 5.0
CVE-2010-4697 [MEDIUM] PHP Regressions
Title: PHP Regressions
Summary: USN 1126-1 introduced two regressions in PHP.
USN 1126-1 fixed several vulnerabilities in PHP. The fix for
CVE-2010-4697 introduced an incorrect reference counting regression
in the Zend engine that caused the PHP interpreter to segfault. This
regression affects Ubuntu 6.06 LTS and Ubuntu 8.04 LTS.
The fixes for CVE-2011-1072 and CVE-2011-1144 introduced a regression
in the PEAR installer that prevented it from creating its cache
directory and reporting errors correctly.
We apologize for the inconvenience.
Original advisory details:
Stephane Chazelas discovered that the /etc/cron.d/php5 cron job for
PHP 5.3.5 allows local users to delete arbitrary files via a symlink
attack on a directory under /var/lib/php5/. (CVE-2011-0441)
Raphael Geisert and Dan R
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2011-04-29·CVSS 5.0
CVE-2011-0421 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Multiple vulnerabilities in PHP.
Stephane Chazelas discovered that the /etc/cron.d/php5 cron job for
PHP 5.3.5 allows local users to delete arbitrary files via a symlink
attack on a directory under /var/lib/php5/. (CVE-2011-0441)
Raphael Geisert and Dan Rosenberg discovered that the PEAR installer
allows local users to overwrite arbitrary files via a symlink attack on
the package.xml file, related to the (1) download_dir, (2) cache_dir,
(3) tmp_dir, and (4) pear-build-download directories. (CVE-2011-1072,
CVE-2011-1144)
Ben Schmidt discovered that a use-after-free vulnerability in the PHP
Zend engine could allow an attacker to cause a denial of service (heap
memory corruption) or possibly execute arbitrary code. (CVE-2010-4697)
Martin Barbella disco
Red Hat
php: integer overflow in shmop_read()
vendor_redhat·2011-03-08·CVSS 7.5
CVE-2011-1092 [HIGH] CWE-190 php: integer overflow in shmop_read()
php: integer overflow in shmop_read()
Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function.
Statement: Red Hat does not consider this to be a security issue. Input passed to these functions should be under the full control of the script author, thus no trust boundary is crossed. Additionally, an administrator would have to disable, or excessively increase the memory_limit settings in the PHP configuration file to trigger this bug.
Package: php (Red Hat Enterprise Linux 4) - Not affected
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
http://bugs.php.net/bug.php?id=54193http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://marc.info/?l=bugtraq&m=133469208622507&w=2http://securityreason.com/securityalert/8130http://support.apple.com/kb/HT5002http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/shmop/shmop.c?r1=306939&r2=309018&pathrev=309018http://www.exploit-db.com/exploits/16966http://www.mandriva.com/security/advisories?name=MDVSA-2011:052http://www.mandriva.com/security/advisories?name=MDVSA-2011:053http://www.openwall.com/lists/oss-security/2011/03/08/11http://www.openwall.com/lists/oss-security/2011/03/08/9http://www.php.net/ChangeLog-5.phphttp://www.php.net/archive/2011.phphttp://www.php.net/releases/5_3_6.phphttp://www.securityfocus.com/bid/46786http://www.vupen.com/english/advisories/2011/0744https://bugzilla.redhat.com/show_bug.cgi?id=683183https://exchange.xforce.ibmcloud.com/vulnerabilities/65988http://bugs.php.net/bug.php?id=54193http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://marc.info/?l=bugtraq&m=133469208622507&w=2http://securityreason.com/securityalert/8130http://support.apple.com/kb/HT5002http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/shmop/shmop.c?r1=306939&r2=309018&pathrev=309018http://www.exploit-db.com/exploits/16966http://www.mandriva.com/security/advisories?name=MDVSA-2011:052http://www.mandriva.com/security/advisories?name=MDVSA-2011:053http://www.openwall.com/lists/oss-security/2011/03/08/11http://www.openwall.com/lists/oss-security/2011/03/08/9http://www.php.net/ChangeLog-5.phphttp://www.php.net/archive/2011.phphttp://www.php.net/releases/5_3_6.phphttp://www.securityfocus.com/bid/46786http://www.vupen.com/english/advisories/2011/0744https://bugzilla.redhat.com/show_bug.cgi?id=683183https://exchange.xforce.ibmcloud.com/vulnerabilities/65988
2011-03-15
Published