Required CVE Record Information
Description
The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function.
References 11 Total
- http://www.php.net/ChangeLog-5.php#5.2.11
- openwall.com: [oss-security] 20091120 Re: CVE request: php 5.3.1 update mailing-list
- news.php.net: [php-announce] 20091119 5.3.1 Release announcement mailing-list
- http://www.php.net/releases/5_2_11.php
- http://www.php.net/ChangeLog-5.php
- openwall.com: [oss-security] 20091120 CVE request: php 5.3.1 update mailing-list
- http://bugs.php.net/bug.php?id=44683
- http://www.php.net/releases/5_3_1.php
- openwall.com: [oss-security] 20090920 Re: CVE Request -- PHP 5 - 5.2.11 mailing-list
- osvdb.org: 58188 vdb-entry
- http://svn.php.net/viewvc?view=revision&revision=287779
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 11 Total
- http://www.php.net/ChangeLog-5.php#5.2.11 x_transferred
- openwall.com: [oss-security] 20091120 Re: CVE request: php 5.3.1 update mailing-listx_transferred
- news.php.net: [php-announce] 20091119 5.3.1 Release announcement mailing-listx_transferred
- http://www.php.net/releases/5_2_11.php x_transferred
- http://www.php.net/ChangeLog-5.php x_transferred
- openwall.com: [oss-security] 20091120 CVE request: php 5.3.1 update mailing-listx_transferred
- http://bugs.php.net/bug.php?id=44683 x_transferred
- http://www.php.net/releases/5_3_1.php x_transferred
- openwall.com: [oss-security] 20090920 Re: CVE Request -- PHP 5 - 5.2.11 mailing-listx_transferred
- osvdb.org: 58188 vdb-entryx_transferred
- http://svn.php.net/viewvc?view=revision&revision=287779 x_transferred