PublicDateAtUSN: 2009-12-01 Candidate: CVE-2009-2626 PublicDate: 2009-12-01 16:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2626 http://securityreason.com/achievement_securityalert/65 https://ubuntu.com/security/notices/USN-882-1 Description: The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=540605 Priority: medium Discovered-by: Maksymilian Arciemowicz Assigned-to: CVSS: Patches_php5: upstream: http://svn.php.net/viewvc?view=revision&revision=284156 (5.3) upstream: http://svn.php.net/viewvc?view=revision&revision=284157 (5.2) upstream: http://svn.php.net/viewvc?view=revision&revision=283944 (5.3) upstream: http://svn.php.net/viewvc?view=revision&revision=283946 (5.2) upstream_php5: needs-triage dapper_php5: released (5.1.2-1ubuntu3.18) hardy_php5: released (5.2.4-2ubuntu5.10) intrepid_php5: released (5.2.6-2ubuntu4.6) jaunty_php5: released (5.2.6.dfsg.1-3ubuntu4.5) karmic_php5: released (5.2.10.dfsg.1-2ubuntu6.4) devel_php5: not-affected (5.2.11.dfsg.1-2ubuntu1)