CVE Database
/

CVE-2012-0788

Back to search

CVE-2012-0788

Published: Feb 14, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2012:0411
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2012:0426
vendor-advisory
x_refsource_SUSE
48668
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now