Vulnerability Name: | CVE-2012-3450 (CCN-77392) |
Assigned: | 2012-08-02 |
Published: | 2012-08-02 |
Updated: | 2013-04-19 |
Summary: | pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Low |
|
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P) 1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Partial | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Partial |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | Denial of Service |
References: | Source: MITRE Type: CNA CVE-2012-3450
Source: SUSE Type: UNKNOWN SUSE-SU-2012:1033
Source: BUGTRAQ Type: UNKNOWN 20120610 [php<=5.4.3] Parsing Bug in PHP PDO prepared statements may lead to access violation
Source: DEBIAN Type: UNKNOWN DSA-2527
Source: DEBIAN Type: DSA-2527 php5 -- several vulnerabilities
Source: MANDRIVA Type: UNKNOWN MDVSA-2012:108
Source: MLIST Type: UNKNOWN [oss-security] 20120802 CVE Request: php5 pdo array overread/crash
Source: MLIST Type: UNKNOWN [oss-security] 20120802 Re: CVE Request: php5 pdo array overread/crash
Source: CCN Type: The PHP Group Web site PHP
Source: CONFIRM Type: UNKNOWN http://www.php.net/ChangeLog-5.php
Source: CCN Type: BID-54777 PHP PDO Memory Access Violation Denial of Service Vulnerability
Source: UBUNTU Type: UNKNOWN USN-1569-1
Source: CONFIRM Type: UNKNOWN https://bugs.php.net/bug.php?id=61755
Source: CONFIRM Type: UNKNOWN https://bugzilla.novell.com/show_bug.cgi?id=769785
Source: XF Type: UNKNOWN php-pdo-dos(77392)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:php:php:5.3.0:*:*:*:*:*:*:*OR cpe:/a:php:php:5.3.1:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.2:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.3:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.4:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.5:*:*:*:*:*:*:*OR cpe:/a:php:php:5.3.6:*:*:*:*:*:*:*OR cpe:/a:php:php:5.3.7:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.8:*:*:*:*:*:*:*OR cpe:/a:php:php:5.3.9:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.10:*:*:*:*:*:*:*OR cpe:/a:php:php:5.3.11:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.12:*:*:*:*:*:*:*OR cpe:/a:php:php:*:*:*:*:*:*:*:* (Version <= 5.3.13)OR cpe:/a:php:php:5.4.0:-:*:*:*:*:*:*OR cpe:/a:php:php:5.4.1:*:*:*:*:*:*:*OR cpe:/a:php:php:5.4.2:*:*:*:*:*:*:*OR cpe:/a:php:php:5.4.3:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:php:php:5.0.3:-:*:*:*:*:*:*OR cpe:/a:php:php:5.0.4:-:*:*:*:*:*:*OR cpe:/a:php:php:5.0.0:-:*:*:*:*:*:*OR cpe:/a:php:php:5.0.5:-:*:*:*:*:*:*OR cpe:/a:php:php:5.1.1:*:*:*:*:*:*:*OR cpe:/a:php:php:5.1.2:-:*:*:*:*:*:*OR cpe:/a:php:php:5.1.4:*:*:*:*:*:*:*OR cpe:/a:php:php:5.0.2:-:*:*:*:*:*:*OR cpe:/a:php:php:5.1.6:*:*:*:*:*:*:*OR cpe:/a:php:php:5.2.0:*:*:*:*:*:*:*OR cpe:/a:php:php:5.2.1:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.3:-:*:*:*:*:*:*OR cpe:/a:php:php:5.0.0:beta1:*:*:*:*:*:*OR cpe:/a:php:php:5.0.0:beta2:*:*:*:*:*:*OR cpe:/a:php:php:5.0.0:beta3:*:*:*:*:*:*OR cpe:/a:php:php:5.0.0:beta4:*:*:*:*:*:*OR cpe:/a:php:php:5.0.0:rc1:*:*:*:*:*:*OR cpe:/a:php:php:5.0.0:rc2:*:*:*:*:*:*OR cpe:/a:php:php:5.0.0:rc3:*:*:*:*:*:*OR cpe:/a:php:php:5.0.1:-:*:*:*:*:*:*OR cpe:/a:php:php:5.1.0:-:*:*:*:*:*:*OR cpe:/a:php:php:5.1.0:-:*:*:*:*:*:*OR cpe:/a:php:php:5.1.3:*:*:*:*:*:*:*OR cpe:/a:php:php:5.1.5:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.2:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.4:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.5:-:*:*:*:*:*:*OR cpe:/a:php:php:5.4.0:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.6:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.7:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.8:*:*:*:*:*:*:*OR cpe:/a:php:php:5.0:rc1:*:*:*:*:*:*OR cpe:/a:php:php:5.0:rc2:*:*:*:*:*:*OR cpe:/a:php:php:5.0:rc3:*:*:*:*:*:*OR cpe:/a:php:php:5.2.9:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.10:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.11:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.0:*:*:*:*:*:*:*OR cpe:/a:php:php:5.2.12:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.1:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.2:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.13:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.3:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.14:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.4:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.5:*:*:*:*:*:*:*OR cpe:/a:php:php:5.3.6:*:*:*:*:*:*:*OR cpe:/a:php:php:5.3.7:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.8:*:*:*:*:*:*:*OR cpe:/a:php:php:5.4.0:beta2:32-bit:*:*:*:*:*OR cpe:/a:php:php:5.2.15:-:*:*:*:*:*:*OR cpe:/a:php:php:5.2.16:*:*:*:*:*:*:*OR cpe:/a:php:php:5.2.17:*:*:*:*:*:*:*OR cpe:/a:php:php:5.3.10:*:*:*:*:*:*:*OR cpe:/a:php:php:5.4.1:*:*:*:*:*:*:*OR cpe:/a:php:php:5.4.2:*:*:*:*:*:*:*OR cpe:/a:php:php:5.3.12:*:*:*:*:*:*:*OR cpe:/a:php:php:5.4.3:*:*:*:*:*:*:*OR cpe:/a:php:php:5.3.11:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.13:*:*:*:*:*:*:*OR cpe:/a:php:php:5.3.14:-:*:*:*:*:*:*OR cpe:/a:php:php:5.3.9:-:*:*:*:*:*:*OR cpe:/a:php:php:5.4.0:beta2:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |