CVE Database
/

CVE-2014-4721

Back to search

CVE-2014-4721

Published: Jul 6, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.

VendorProductVersions

n/a

n/a

affected
n/a

References

54553
third-party-advisory
x_refsource_SECUNIA
RHSA-2014:1766
vendor-advisory
x_refsource_REDHAT
DSA-2974
vendor-advisory
x_refsource_DEBIAN
59794
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2014:0945
vendor-advisory
x_refsource_SUSE
RHSA-2014:1765
vendor-advisory
x_refsource_REDHAT
59831
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2014:1236
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now