10
CVSSv2

CVE-2012-2688

Published: 20/07/2012 Updated: 22/12/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP prior to 5.3.15 and 5.4.x prior to 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

Vulnerable Product Search on Vulmon Subscribe to Product

php php

php php 5.3.1

php php 5.3.7

php php 5.3.12

php php 5.3.8

php php 5.3.11

php php 5.3.4

php php 5.3.3

php php 5.3.0

php php 5.3.2

php php 5.3.10

php php 5.2.15

php php 5.2.11

php php 5.2.7

php php 5.2.1

php php 5.2.2

php php 5.1.5

php php 5.0.5

php php 5.0.2

php php 5.0.1

php php 4.3.2

php php 4.3.11

php php 4.4.9

php php 4.2.3

php php 4.3.8

php php 4.3.9

php php 4.0

php php 4.0.1

php php 4.0.3

php php 4.0.2

php php 3.0.13

php php 5.3.6

php php 5.3.5

php php 5.2.12

php php 5.2.10

php php 5.2.6

php php 5.2.4

php php 5.1.2

php php 5.1.1

php php 5.0.0

php php 4.3.6

php php 4.3.5

php php 4.2.1

php php 4.4.6

php php 4.4.7

php php 4.4.2

php php 4.4.3

php php 4.0.6

php php 4.1.0

php php 4.0.7

php php 3.0.2

php php 3.0.18

php php 3.0.7

php php 3.0.8

php php 5.4.3

php php 5.4.0

php php 5.2.9

php php 5.2.16

php php 5.2.0

php php 5.2.8

php php 5.2.17

php php 5.1.3

php php 5.0.4

php php 5.0.3

php php 4.3.4

php php 4.3.3

php php 4.2.2

php php 4.4.5

php php 4.4.0

php php 4.4.1

php php 4.0.0

php php 4.1.2

php php 4.1.1

php php 3.0.1

php php 3.0

php php 3.0.17

php php 3.0.16

php php 3.0.9

php php 1.0

php php 5.4.4

php php 3.0.12

php php 3.0.15

php php 3.0.14

php php 2.0b10

php php 2.0

php php 5.3.9

php php 5.3.13

php php 5.2.13

php php 5.2.5

php php 5.2.3

php php 5.2.14

php php 5.1.0

php php 5.1.6

php php 5.1.4

php php 4.3.10

php php 4.3.1

php php 4.4.8

php php 4.2.0

php php 4.3.0

php php 4.3.7

php php 4.4.4

php php 4.0.5

php php 4.0.4

php php 3.0.11

php php 3.0.10

php php 3.0.4

php php 3.0.3

php php 3.0.5

php php 3.0.6

php php 5.4.1

php php 5.4.2

Vendor Advisories

Debian Bug report logs - #683274 CVE-2012-2688 Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Mon, 30 Jul 2012 12:36:02 UTC Severity: grave Tags: ...
Several security issues were fixed in PHP ...
Synopsis Moderate: php security, bug fix and enhancement update Type/Severity Security Advisory: Moderate Topic Updated php packages that fix three security issues, several bugs, and addvarious enhancements are now available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this up ...
Synopsis Moderate: php53 security, bug fix and enhancement update Type/Severity Security Advisory: Moderate Topic Updated php53 packages that fix multiple security issues, several bugs, andadd one enhancement are now available for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this ...
Synopsis Critical: php security update Type/Severity Security Advisory: Critical Topic Updated php packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having criticalsecurity impact Common Vulnerability Scori ...
Several vulnerabilities have been discovered in PHP, the web scripting language The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2012-2688 A buffer overflow in the scandir() function could lead to denial of service or the execution of arbitrary code CVE-2012-3450 It was discovered that inconsistent p ...
Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5315 and 54x before 545 has unknown impact and remote attack vectors, related to an "overflow" ...