CVE-2008-5557

HIGH

Description

Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not properly handled during Unicode conversion, related to the (1) mb_convert_encoding, (2) mb_check_encoding, (3) mb_convert_variables, and (4) mb_parse_str functions.

References

http://archives.neohapsis.com/archives/fulldisclosure/2008-12/0477.html

http://bugs.php.net/bug.php?id=45722

http://cvs.php.net/viewvc.cgi/php-src/ext/mbstring/libmbfl/filters/mbfilter_htmlent.c?r1=1.7&r2=1.8

http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444

http://lists.apple.com/archives/security-announce/2009/May/msg00002.html

http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html

http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html

http://marc.info/?l=bugtraq&m=124654546101607&w=2

http://marc.info/?l=bugtraq&m=125631037611762&w=2

http://secunia.com/advisories/34642

http://secunia.com/advisories/35003

http://secunia.com/advisories/35074

http://secunia.com/advisories/35306

http://secunia.com/advisories/35650

http://securitytracker.com/id?1021482

http://support.apple.com/kb/HT3549

http://wiki.rpath.com/Advisories:rPSA-2009-0035

http://www.debian.org/security/2009/dsa-1789

http://www.mandriva.com/security/advisories?name=MDVSA-2009:045

http://www.php.net/ChangeLog-5.php#5.2.7

http://www.redhat.com/support/errata/RHSA-2009-0350.html

http://www.securityfocus.com/archive/1/501376/100/0/threaded

http://www.securityfocus.com/bid/32948

http://www.us-cert.gov/cas/techalerts/TA09-133A.html

http://www.vupen.com/english/advisories/2009/1297

https://exchange.xforce.ibmcloud.com/vulnerabilities/47525

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10286

https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html

https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html

Details

Source: MITRE

Published: 2008-12-23

Updated: 2018-10-11

Type: CWE-119

Risk Information

CVSS v2.0

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:php:php:4.3.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.3:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.4:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.5:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.6:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.7:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.8:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.9:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.10:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.11:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.3:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.4:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.5:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.6:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.7:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.8:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.9:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.0:beta1:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.0:beta2:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.0:beta3:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.0:beta4:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.0:rc1:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.0:rc2:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.0:rc3:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.3:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.4:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.5:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.3:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.4:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.5:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.6:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.2.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.2.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.2.3:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.2.4:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.2.5:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.2.6:*:*:*:*:*:*:*

Tenable Plugins

View all (27 total)

IDNameProductFamilySeverity
4779PHP 5.x < 5.2.7 Multiple VulnerabilitiesNessus Network MonitorWeb Servers
high
78229F5 Networks BIG-IP : PHP vulnerability (SOL9761)NessusF5 Networks Local Security Checks
critical
67818Oracle Linux 5 : php (ELSA-2009-0338)NessusOracle Linux Local Security Checks
critical
67817Oracle Linux 3 / 4 : php (ELSA-2009-0337)NessusOracle Linux Local Security Checks
critical
60561Scientific Linux Security Update : php on SL3.x, SL4.x, SL5.x i386/x86_64NessusScientific Linux Local Security Checks
critical
46015HP System Management Homepage < 6.0.0.96 / 6.0.0-95 Multiple VulnerabilitiesNessusWeb Servers
critical
44892GLSA-201001-03 : PHP: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
43732CentOS 5 : php (CESA-2009:0338)NessusCentOS Local Security Checks
critical
41475SuSE 10 Security Update : PHP5 (ZYPP Patch Number 5909)NessusSuSE Local Security Checks
critical
41287SuSE9 Security Update : PHP4 (YOU Patch Number 12382)NessusSuSE Local Security Checks
critical
40186openSUSE Security Update : apache2-mod_php5 (apache2-mod_php5-441)NessusSuSE Local Security Checks
critical
39915openSUSE Security Update : apache2-mod_php5 (apache2-mod_php5-441)NessusSuSE Local Security Checks
critical
38957Fedora 9 : maniadrive-1.2-13.fc9 / php-5.2.9-2.fc9 (2009-3848)NessusFedora Local Security Checks
critical
38956Fedora 10 : maniadrive-1.2-13.fc10 / php-5.2.9-2.fc10 (2009-3768)NessusFedora Local Security Checks
critical
38744Mac OS X 10.5.x < 10.5.7 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
critical
38691Debian DSA-1789-1 : php5 - several vulnerabilitiesNessusDebian Local Security Checks
critical
36677Mandriva Linux Security Advisory : php (MDVSA-2009:045)NessusMandriva Local Security Checks
critical
36665Ubuntu 6.06 LTS / 7.10 / 8.04 LTS / 8.10 : php5 vulnerabilities (USN-720-1)NessusUbuntu Local Security Checks
critical
36098RHEL 5 : php (RHSA-2009:0338)NessusRed Hat Local Security Checks
critical
36097RHEL 3 / 4 : php (RHSA-2009:0337)NessusRed Hat Local Security Checks
critical
36089CentOS 3 / 4 : php (CESA-2009:0337)NessusCentOS Local Security Checks
critical
35939FreeBSD : php-mbstring -- php mbstring buffer overflow vulnerability (a2074ac6-124c-11de-a964-0030843d3802)NessusFreeBSD Local Security Checks
critical
35606openSUSE 10 Security Update : apache2-mod_php5 (apache2-mod_php5-5934)NessusSuSE Local Security Checks
critical
35043PHP 5 < 5.2.7 Multiple VulnerabilitiesNessusCGI abuses
high
5023Mac OS X 10.5 < 10.5.7 Multiple VulnerabilitiesNessus Network MonitorGeneric
critical
801088PHP 5 < 5.2.7 Multiple VulnerabilitiesLog Correlation EngineWeb Servers
high
800792Mac OS X 10.5 < 10.5.7 Multiple VulnerabilitiesLog Correlation EngineOperating System Detection
high