Overview
PHP fails to properly sanitize input passed to the getSymbol function in a way that could allow and attacker to cause a segmentation fault.
Description
PHP is a scripting language that is designed for web-based applications and can be embedded directly into HTML.
|
Impact
A remote attacker could cause a segmentation fault in PHP, leading to a denial of service. |
Solution
Upgrade |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
Thanks to Maksymilian Arciemowicz for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
| CVE IDs: | None |
| Severity Metric: | 5.04 |
| Date Public: | 2010-11-19 |
| Date First Published: | 2010-11-30 |
| Date Last Updated: | 2010-11-30 20:28 UTC |
| Document Revision: | 9 |