FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-0421

This CVE name corresponds to:

Entered Topic
2011-03-25 php -- ZipArchive segfault with FL_UNCHANGED on empty archive

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-0421
Phase Assigned(20110111)

Description

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.

References

Source Reference
SREASONRES 20110318 libzip 0.9.3 _zip_name_locate NULL Pointer Dereference (incl PHP 5.3.5)
BUGTRAQ 20110318 libzip 0.9.3 _zip_name_locate NULL Pointer Dereference (incl PHP 5.3.5)
EXPLOIT-DB 17004
CONFIRM http://bugs.php.net/bug.php?id=53885
CONFIRM http://svn.php.net/viewvc/?view=revision&revision=307867
CONFIRM http://www.php.net/ChangeLog-5.php
CONFIRM http://www.php.net/archive/2011.php
CONFIRM http://www.php.net/releases/5_3_6.php
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=688735
CONFIRM http://support.apple.com/kb/HT5002
APPLE APPLE-SA-2011-10-12-3
DEBIAN DSA-2266
FEDORA FEDORA-2011-3614
FEDORA FEDORA-2011-3636
FEDORA FEDORA-2011-3666
MANDRIVA MDVSA-2011:052
MANDRIVA MDVSA-2011:053
MANDRIVA MDVSA-2011:099
SUSE SUSE-SR:2011:009
BID 46354
SECUNIA 43621
SREASON 8146
VUPEN ADV-2011-0744
VUPEN ADV-2011-0764
VUPEN ADV-2011-0890
XF libzip-zipnamelocate-dos(66173)