Vigil@nce: PHP, denials of service
January 2012 by Vigil@nce
This bulletin was written by Vigil@nce : http://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
An attacker can use malicious PHP code, in order to create a denial of service.
Severity: 1/4
Creation date: 23/01/2012
IMPACTED PRODUCTS
PHP
DESCRIPTION OF THE VULNERABILITY
Two denials of service were announced in PHP.
An attacker can stop a PDO (PHP Data Objects) object, in order to stop Apache httpd. [severity:1/4; 55776, CVE-2012-0788]
An attacker can convert a date containing a TimeZone, in order to create a memory leak. [severity:1/4; 53502, CVE-2012-0789]
An attacker can therefore use malicious PHP code, in order to create a denial of service.
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN





News













