CVE Database
/

CVE-2004-1018

Back to search

CVE-2004-1018

Published: Dec 8, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2005:032
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:10949
vdb-entry
signature
x_refsource_OVAL
MDKSA-2005:072
vendor-advisory
x_refsource_MANDRAKE
12411
vdb-entry
x_refsource_OSVDB
RHSA-2005:816
vendor-advisory
x_refsource_REDHAT
MDKSA-2004:151
vendor-advisory
x_refsource_MANDRAKE
FLSA:2344
vendor-advisory
x_refsource_FEDORA
HPSBMA01212
vendor-advisory
x_refsource_HP
12045
vdb-entry
x_refsource_BID
USN-99-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now