Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 01:16
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html - | |
References | () http://marc.info/?l=bugtraq&m=133469208622507&w=2 - | |
References | () http://pastebin.com/mXGidCsd - Exploit | |
References | () http://secunia.com/advisories/40860 - | |
References | () http://support.apple.com/kb/HT4312 - | |
References | () http://twitter.com/i0n1c/statuses/16373156076 - | |
References | () http://twitter.com/i0n1c/statuses/16447867829 - | |
References | () http://www.debian.org/security/2010/dsa-2089 - | |
References | () http://www.securityfocus.com/bid/40948 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=605641 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/59610 - |
Information
Published : 2010-06-24 12:30
Updated : 2024-11-21 01:16
NVD link : CVE-2010-2225
Mitre link : CVE-2010-2225
CVE.ORG link : CVE-2010-2225
JSON object : View
Products Affected
php
- php
CWE
CWE-399
Resource Management Errors