Back to search
CVE-2011-1148
Published: Mar 18, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
Use-after-free vulnerability in the substr_replace function in PHP 5.3.6 and earlier allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by using the same variable for multiple arguments.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
HPSBOV02763
vendor-advisory
x_refsource_HP
http://support.apple.com/kb/HT5130
x_refsource_CONFIRM
49241
vdb-entry
x_refsource_BID
[oss-security] 20110313 CVE request: PHP substr_replace() use-after-free
mailing-list
x_refsource_MLIST
MDVSA-2011:165
vendor-advisory
x_refsource_MANDRIVA
[oss-security] 20110313 Re: CVE request: PHP substr_replace() use-after-free
mailing-list
x_refsource_MLIST
APPLE-SA-2012-02-01-1
vendor-advisory
x_refsource_APPLE
[oss-security] 20110313 Re: CVE request: PHP substr_replace() use-after-free
mailing-list
x_refsource_MLIST
http://bugs.php.net/bug.php?id=54238
x_refsource_CONFIRM
SSRT100826
vendor-advisory
x_refsource_HP
RHSA-2011:1423
vendor-advisory
x_refsource_REDHAT
http://www.php.net/ChangeLog-5.php#5.3.7
x_refsource_CONFIRM
php-substrreplace-code-exec(66080)
vdb-entry
x_refsource_XF
46843
vdb-entry
x_refsource_BID
http://www.php.net/archive/2011.php#id2011-08-18-1
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now