---
title: "CVE-2010-4699\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2010-4699?format=md
keywords: index, follow
---

# CVE-2010-4699

Publication date 18 January 2011

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The iconv\_mime\_decode\_headers function in the Iconv extension in PHP before
5.3.4 does not properly handle encodings that are unrecognized by the iconv
and mbstring (aka Multibyte String) implementations, which allows remote
attackers to trigger an incomplete output array, and possibly bypass spam
detection or have unspecified other impact, via a crafted Subject header in
an e-mail message, as demonstrated by the ks\_c\_5601-1987 character set.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2010-4699?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| php5 | 10.10 maverick | Ignored |
| 10.04 LTS lucid | Ignored |
| 9.10 karmic | Ignored |
| 8.04 LTS hardy | Ignored |
| 6.06 LTS dapper | Ignored |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2010-4699?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

Upstream doesn't think this has a security impact. Also, see
Red Hat bug. Marking as ignored.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| php5 | * Upstream:   <http://svn.php.net/viewvc/?view=revision&revision=303890> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4699)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2010-4699)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2010-4699)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2010-4699)

### Other references

* <http://coding.derkeiler.com/Archive/PHP/php.general/2007-04/msg00605.html>
* <https://www.cve.org/CVERecord?id=CVE-2010-4699>
