5
CVSSv2

CVE-2013-3735

Published: 31/05/2013 Updated: 11/04/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The Zend Engine in PHP prior to 5.4.16 RC1, and 5.5.0 before RC2, does not properly determine whether a parser error occurred, which allows context-dependent malicious users to cause a denial of service (memory consumption and application crash) via a crafted function definition, as demonstrated by an attack within a shared web-hosting environment. NOTE: the vendor's php.net/security-note.php page says "for critical security situations you should be using OS-level security by running multiple web servers each as their own user id.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.4.12

php php 5.4.14

php php 5.4.8

php php 5.4.9

php php 5.4.11

php php 5.4.10

php php 5.4.2

php php 5.4.5

php php 5.4.6

php php 5.4.13

php php 5.4.0

php php 5.4.3

php php 5.4.1

php php 5.4.7

php php

php php 5.4.4

php php 5.5.0

Vendor Advisories

** DISPUTED ** The Zend Engine in PHP before 5416 RC1, and 550 before RC2, does not properly determine whether a parser error occurred, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted function definition, as demonstrated by an attack within a shared web-hosting envir ...