CVE-2010-2097

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The (1) iconv_mime_decode, (2) iconv_substr, and (3) iconv_mime_encode functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.

References

http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html

http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html

http://marc.info/?l=bugtraq&m=133469208622507&w=2

http://php-security.org/2010/05/18/mops-2010-032-php-iconv_mime_decode-interruption-information-leak-vulnerability/index.html

http://php-security.org/2010/05/18/mops-2010-033-php-iconv_substr-interruption-information-leak-vulnerability/index.html

http://php-security.org/2010/05/18/mops-2010-034-php-iconv_mime_encode-interruption-information-leak-vulnerability/index.html

Details

Source: MITRE

Published: 2010-05-27

Updated: 2016-08-23

Type: CWE-200

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Tenable Plugins

View all (10 total)

IDNameProductFamilySeverity
75429openSUSE Security Update : apache2-mod_php5 (openSUSE-SU-2010:0599-1)NessusSuSE Local Security Checks
high
56459GLSA-201110-06 : PHP: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
50890SuSE 11 / 11.1 Security Update : Apache 2 (SAT Patch Numbers 2880 / 2881)NessusSuSE Local Security Checks
high
49830SuSE 10 Security Update : Linux kernel (ZYPP Patch Number 7110)NessusSuSE Local Security Checks
high
49752openSUSE Security Update : apache2-mod_php5 (openSUSE-SU-2010:0678-1)NessusSuSE Local Security Checks
high
49210openSUSE Security Update : apache2-mod_php5 (openSUSE-SU-2010:0599-1)NessusSuSE Local Security Checks
high
48245PHP 5.3 < 5.3.3 Multiple VulnerabilitiesNessusCGI abuses
high
48244PHP 5.2 < 5.2.14 Multiple VulnerabilitiesNessusCGI abuses
high
801070PHP < 5.3.3 / 5.2.14 Multiple VulnerabilitiesLog Correlation EngineWeb Servers
high
5616PHP < 5.2.14 / 5.3.x < 5.3.3 Multiple VulnerabilitiesNessus Network MonitorWeb Servers
high