Oval Definition:oval:com.ubuntu.precise:def:20122336000
Revision Date:2012-05-11Version:1
Title:CVE-2012-2336 on Ubuntu 12.04 LTS (precise) - low.
Description:sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2012-2336
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'php5' package in precise was vulnerable but has been fixed (note: '5.3.10-1ubuntu3.2').
  • BACK