FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-0831

This CVE name corresponds to:

Entered Topic
2012-04-28 php -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-0831
Phase Assigned(20120119)

Description

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

References

Source Reference
CONFIRM http://svn.php.net/viewvc?view=revision&revision=323016
CONFIRM https://launchpadlibrarian.net/92454212/php5_5.3.2-1ubuntu4.13.diff.gz
CONFIRM http://support.apple.com/kb/HT5501
APPLE APPLE-SA-2012-09-19-2
FEDORA FEDORA-2012-6907
FEDORA FEDORA-2012-6911
REDHAT RHSA-2013:1307
SUSE openSUSE-SU-2012:0426
UBUNTU USN-1358-1
BID 51954
SECUNIA 48668
SECUNIA 55078
XF php-magicquotesgpc-sec-bypass(73125)