VDB

GCVE-110-MAGEIA-2013-379

GCVE-110-MAGEIA-2013-379
Advisory Published
Vulnetix · Advisory published December 19, 2013
Updated php packages fix security vulnerabilities: Stefan Esser discovered that PHP incorrectly parsed certificates. An attacker could use a malformed certificate to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2013-6420). It was discovered that PHP incorrectly handled DateInterval objects. An attacker could use this issue to cause PHP to crash, resulting in a denial of service (CVE-2013-6712).

Affected Products

VendorProductVersionsPlatforms
Mageiaphp-apc0 (affected), 3.1.14-7.5.mga3 (unaffected)
Mageiaphp-gd-bundled5.4.23-1.mga3 (unaffected), 0 (affected)
Mageiaphp5.4.23-1.mga3 (unaffected), 0 (affected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›