Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2010-3709

Published: 8 November 2010

The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.

Notes

AuthorNote
mdeslaur
PoC here: http://securityreason.com/achievement_securityalert/90
sbeattie
dapper version of php does not include zip support

Priority

Low

Status

Package Release Status
php5
Launchpad, Ubuntu, Debian
dapper Not vulnerable

hardy
Released (5.2.4-2ubuntu5.13)
karmic
Released (5.2.10.dfsg.1-2ubuntu6.6)
lucid
Released (5.3.2-1ubuntu4.6)
maverick
Released (5.3.3-1ubuntu9.2)
upstream Needs triage

Patches:
upstream: http://svn.php.net/viewvc?view=revision&revision=304505