5
CVSSv2

CVE-2011-0420

Published: 19/02/2011 Updated: 10/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependent malicious users to cause a denial of service (crash) via an invalid size argument, which triggers a NULL pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.3.5

Vendor Advisories

Several vulnerabilities were discovered in PHP, which could lead to denial of service or potentially the execution of arbitrary code CVE-2010-2531 An information leak was found in the var_export() function CVE-2011-0421 The Zip module could crash CVE-2011-0708 An integer overflow was discovered in the Exif module CVE-2011-1466 An i ...
USN 1126-1 introduced two regressions in PHP ...
Multiple vulnerabilities in PHP ...

Exploits

PHP version 525 suffers from a grapheme_extract() null pointer dereference vulnerability ...
Source: securityreasoncom/securityalert/8087 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ PHP 535 grapheme_extract() NULL Pointer Dereference ] Author: Maksymilian Arciemowicz securityreasoncom/ cxibnet/ Date: - - Dis: 09122010 - - Pub: 17022011 CVE: CVE-2011-0420 CERT: VU#210829 Affected Software: - - PHP 5 ...
source: wwwsecurityfocuscom/bid/46429/info PHP is prone to a denial-of-service vulnerability caused by a NULL-pointer dereference An attacker can exploit this issue to cause an appliation written in PHP to crash, denying service to legitimate users PHP 535 is vulnerable; other versions may also be affected The following proof-of- ...