CVE Database
/

CVE-2009-1272

Back to search

CVE-2009-1272

Published: Apr 8, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

VendorProductVersions

n/a

n/a

affected
n/a

References

APPLE-SA-2009-09-10-2
vendor-advisory
x_refsource_APPLE
35685
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2009:012
vendor-advisory
x_refsource_SUSE
36701
third-party-advisory
x_refsource_SECUNIA
HPSBMA02447
vendor-advisory
x_refsource_HP
SSRT090062
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now