5
CVSSv2

CVE-2010-4150

Published: 07/12/2010 Updated: 19/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Double free vulnerability in the imap_do_open function in the IMAP extension (ext/imap/php_imap.c) in PHP 5.2 prior to 5.2.15 and 5.3 prior to 5.3.4 allows malicious users to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.2.4

php php 5.2.3

php php 5.3.2

php php 5.2.11

php php 5.2.0

php php 5.3.0

php php 5.3.1

php php 5.2.12

php php 5.2.10

php php 5.2.13

php php 5.2.2

php php 5.3.3

php php 5.2.14

php php 5.2.1

Vendor Advisories

Stephane Chazelas discovered that the cronjob of the PHP 5 package in Debian suffers from a race condition which might be used to remove arbitrary files from a system (CVE-2011-0441) When upgrading your php5-common package take special care to accept the changes to the /etc/crond/php5 file Ignoring them would leave the system vulnerable For the ...