CVE-2010-2093
Publication date 27 May 2010
Last updated 24 July 2024
Ubuntu priority
Use-after-free vulnerability in the request shutdown functionality in PHP 5.2 before 5.2.13 and 5.3 before 5.3.2 allows context-dependent attackers to cause a denial of service (crash) via a stream context structure that is freed before destruction occurs.
Status
Package | Ubuntu Release | Status |
---|---|---|
php5 | 11.10 oneiric | Ignored |
11.04 natty | Ignored | |
10.10 maverick | Ignored | |
10.04 LTS lucid | Ignored | |
9.10 karmic | Ignored end of life | |
9.04 jaunty | Ignored end of life | |
8.04 LTS hardy | Ignored | |
6.06 LTS dapper | Ignored end of life |
Notes
jdstrand
PoC: http://php-security.org/2010/05/12/mops-2010-022-php-stream-context-use-after-free-on-request-shutdown-vulnerability/index.html
mdeslaur
unfixed in 5.3.3 This is MOPS-2010-022
sbeattie
upstream considers a fix invasive, according to referenced oss-security post
mdeslaur
upstream is ignoring this, so are we.