---
title: "CVE-2010-1915\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2010-1915?format=md
keywords: index, follow
---

# CVE-2010-1915

Publication date 12 May 2010

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The preg\_quote function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2
allows context-dependent attackers to obtain sensitive information (memory
contents) by causing a userspace interruption of an internal function,
related to the call time pass by reference feature, modification of ZVALs
whose values are not updated in the associated local variables, and access
of previously-freed memory.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2010-1915?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| php5 | 10.04 LTS lucid | Ignored |
| 9.10 karmic | Ignored |
| 9.04 jaunty | Ignored |
| 8.04 LTS hardy | Ignored |
| 6.06 LTS dapper | Ignored |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

see CVE-2010-1864 for patch
interruption issue, safe\_mode - open\_basedir bypass, ignoring
This is MOPS-2010-017

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1915)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2010-1915)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2010-1915)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2010-1915)

### Other references

* <http://www.php-security.org/2010/05/09/mops-2010-017-php-preg_quote-interruption-information-leak-vulnerability/index.html>
* <https://www.cve.org/CVERecord?id=CVE-2010-1915>
