CVE-2012-3450

Publication date 6 August 2012

Last updated 24 July 2024


Ubuntu priority

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 12.04 LTS precise
Fixed 5.3.10-1ubuntu3.4
11.10 oneiric
Fixed 5.3.6-13ubuntu3.9
11.04 natty
Fixed 5.3.5-1ubuntu7.11
10.04 LTS lucid
Fixed 5.3.2-1ubuntu4.18
8.04 LTS hardy
Fixed 5.2.4-2ubuntu5.26

Notes


mdeslaur

pdo_sql_parser.re generates pdo_sql_parser.c, so both need to be patched.