Vulnerability Name: | CVE-2004-0958 (CCN-17393) | ||||||||||||
Assigned: | 2004-09-15 | ||||||||||||
Published: | 2004-09-15 | ||||||||||||
Updated: | 2017-10-11 | ||||||||||||
Summary: | php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: CCN Type: VulnWatch Mailing List, Wed Sep 15 2004 - 11:59:41 CDT PHP Vulnerability N. 1 Source: VULNWATCH Type: UNKNOWN 20040915 [VulnWatch] PHP Vulnerability N. 1 Source: CCN Type: PHP Web site Source Log for php-src/main/php_variables.c Source: MITRE Type: CNA CVE-2004-0958 Source: BUGTRAQ Type: UNKNOWN 20040915 PHP Vulnerability N. 1 Source: CCN Type: RHSA-2004-687 php security update Source: CCN Type: SA12560 PHP Memory Leak and Arbitrary File Location Upload Vulnerabilities Source: SECUNIA Type: UNKNOWN 12560 Source: CCN Type: SECTRACK ID: 1011279 PHP Array Parsing Error in php_variables May Disclose Memory Contents via phpinfo() Source: SECTRACK Type: UNKNOWN 1011279 Source: CCN Type: GLSA-200410-04 PHP: Memory disclosure and arbitrary location file upload Source: CCN Type: Fedora Update Notification FEDORA-2004-567 Fedora: php-4.3.10-2.4 update Source: REDHAT Type: Patch, Vendor Advisory RHSA-2004:687 Source: CCN Type: BID-11334 PHP PHP_Variables Remote Memory Disclosure Vulnerability Source: FEDORA Type: UNKNOWN FLSA:2344 Source: XF Type: UNKNOWN php-phpinfo-disclose-memory(17393) Source: XF Type: UNKNOWN php-phpinfo-disclose-memory(17393) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10863 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |