CVE-2010-1866

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative chunk size, which bypasses a signed comparison, related to an integer overflow in the chunk size decoder.

References

http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html

http://php-security.org/2010/05/02/mops-2010-003-php-dechunk-filter-signed-comparison-vulnerability/index.html

Details

Source: MITRE

Published: 2010-05-07

Updated: 2010-09-30

Type: CWE-189

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (5 total)

IDNameProductFamilySeverity
75429openSUSE Security Update : apache2-mod_php5 (openSUSE-SU-2010:0599-1)NessusSuSE Local Security Checks
high
56459GLSA-201110-06 : PHP: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
50890SuSE 11 / 11.1 Security Update : Apache 2 (SAT Patch Numbers 2880 / 2881)NessusSuSE Local Security Checks
high
49306Ubuntu 6.06 LTS / 8.04 LTS / 9.04 / 9.10 / 10.04 LTS : php5 vulnerabilities (USN-989-1)NessusUbuntu Local Security Checks
high
49210openSUSE Security Update : apache2-mod_php5 (openSUSE-SU-2010:0599-1)NessusSuSE Local Security Checks
high