Vulnerability Name:
CVE-2010-2484 (CCN-60741)
Assigned:
2010-07-22
Published:
2010-07-22
Updated:
2016-08-23
Summary:
The strrchr function in PHP 5.2 before 5.2.14 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler.
CVSS v3 Severity:
5.3 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
None
Availibility (A):
None
CVSS v2 Severity:
5.0 Medium
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
)
3.7 Low
(Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
5.0 Medium
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
)
3.7 Low
(CCN Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
Vulnerability Type:
CWE-200
Vulnerability Consequences:
Obtain Information
References:
Source: MITRE
Type: CNA
CVE-2010-2484
Source: APPLE
Type: UNKNOWN
APPLE-SA-2010-08-24-1
Source: APPLE
Type: UNKNOWN
APPLE-SA-2010-11-10-1
Source: SUSE
Type: UNKNOWN
SUSE-SR:2010:018
Source: HP
Type: UNKNOWN
SSRT100826
Source: CCN
Type: Apple Web site
About Security Update 2010-005
Source: CONFIRM
Type: UNKNOWN
http://support.apple.com/kb/HT4312
Source: CONFIRM
Type: UNKNOWN
http://support.apple.com/kb/HT4435
Source: CCN
Type: OSVDB ID: 66804
PHP strrchr() Function Interruption Array Leak Memory Disclosure
Source: CCN
Type: PHP Web Site
PHP 5 ChangeLog
Source: CONFIRM
Type: UNKNOWN
http://www.php.net/releases/5_2_14.php
Source: CCN
Type: BID-41991
PHP Versions Prior to 5.3.3/5.2.14 Multiple Vulnerabilities
Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=619324
Source: XF
Type: UNKNOWN
php-strrchr-information-disclosure(60741)
Source: SUSE
Type: SUSE-SR:2010:018
SUSE Security Summary Report
Vulnerable Configuration:
Configuration 1
:
cpe:/a:php:php:5.2.0:*:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.1:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.2:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.3:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.4:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.5:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.6:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.8:*:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.9:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.10:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.11:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.12:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.13:-:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:php:php:5.2.0:*:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.1:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.3:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.2:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.4:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.5:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.6:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.7:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.8:*:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.9:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.10:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.11:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.3.0:*:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.12:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.3.1:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.3.2:-:*:*:*:*:*:*
OR
cpe:/a:php:php:5.2.13:-:*:*:*:*:*:*
AND
cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:x86_64:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:x86-64:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*
OR
cpe:/o:mandriva:linux:2009.0:*:*:*:*:*:*:*
OR
cpe:/o:mandriva:linux:2009.0:-:x86_64:*:*:*:*:*
OR
cpe:/o:mandriva:linux:2009.1:*:*:*:*:*:*:*
OR
cpe:/o:mandriva:linux:2009.1:*:*:*:x86_64:*:*:*
OR
cpe:/o:apple:mac_os_x_server:10.6.4:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.6.4:*:*:*:*:*:*:*
OR
cpe:/o:mandriva:enterprise_server:5:*:*:*:*:*:*:*
OR
cpe:/o:mandriva:enterprise_server:5:*:*:*:x86_64:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.opensuse.security:def:20102484
V
CVE-2010-2484
2015-11-16
oval:org.mitre.oval:def:21065
P
USN-1231-1 -- php5 vulnerabilities
2014-06-30
BACK
php
php 5.2.0
php
php 5.2.1
php
php 5.2.2
php
php 5.2.3
php
php 5.2.4
php
php 5.2.5
php
php 5.2.6
php
php 5.2.8
php
php 5.2.9
php
php 5.2.10
php
php 5.2.11
php
php 5.2.12
php
php 5.2.13
php
php 5.2.0
php
php 5.2.1 -
php
php 5.2.3 -
php
php 5.2.2 -
php
php 5.2.4 -
php
php 5.2.5 -
php
php 5.2.6 -
php
php 5.2.7 -
php
php 5.2.8
php
php 5.2.9 -
php
php 5.2.10 -
php
php 5.2.11 -
php
php 5.3.0
php
php 5.2.12 -
php
php 5.3.1 -
php
php 5.3.2 -
php
php 5.2.13 -
mandrakesoft
mandrake linux corporate server 4.0
mandrakesoft
mandrake linux corporate server 4.0
mandrakesoft
mandrake linux 2008.0
mandrakesoft
mandrake linux 2008.0
mandriva
linux 2009.0
mandriva
linux 2009.0 -
mandriva
linux 2009.1
mandriva
linux 2009.1
apple
mac os x server 10.6.4
apple
mac os x 10.6.4
mandriva
enterprise server 5
mandriva
enterprise server 5