FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-2688

This CVE name corresponds to:

Entered Topic
2012-07-23 php -- potential overflow in _php_stream_scandir

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-2688
Phase Assigned(20120514)

Description

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

References

Source Reference
CONFIRM http://www.php.net/ChangeLog-5.php
CONFIRM http://support.apple.com/kb/HT5501
APPLE APPLE-SA-2012-09-19-2
DEBIAN DSA-2527
MANDRIVA MDVSA-2012:108
REDHAT RHSA-2013:1307
SUSE SUSE-SU-2012:1033
SUSE SUSE-SU-2012:1034
SUSE openSUSE-SU-2012:0976
UBUNTU USN-1569-1
SECUNIA 55078