CVE-2009-1271
Summary
| CVE | CVE-2009-1271 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-04-08 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Php | Php | 5.2.0 | All | All | All |
| Application | Php | Php | 5.2.1 | All | All | All |
| Application | Php | Php | 5.2.2 | All | All | All |
| Application | Php | Php | 5.2.3 | All | All | All |
| Application | Php | Php | 5.2.4 | All | All | All |
| Application | Php | Php | 5.2.4 | All | windows | All |
| Application | Php | Php | 5.2.5 | All | All | All |
| Application | Php | Php | 5.2.6 | All | All | All |
| Application | Php | Php | 5.2.7 | All | All | All |
| Application | Php | Php | 5.2.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cvs.php.net/viewvc.cgi/php-src/ext/json/JSON_parser.c | af854a3a-2127-422b-91ae-364da2661108 | cvs.php.net | |
| Fedora update for php - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 9 Update: maniadrive-1.2-13.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian update for php-json-ext - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Ubuntu update for php5 - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-761-2: PHP vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Support / Security / Advisories / / MDVSA-2009:090 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| PHP: PHP 5.2.9 Release Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | Vendor Advisory |
| USN-761-1: PHP vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| Ubuntu update for php5 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1775-1 php-json-ext | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora 10 Update: maniadrive-1.2-13.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian update for php5 - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Security Update 2009-005 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| oss-security - CVE request: PHP 5.2.9 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Debian update for php5 - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| APPLE-SA-2009-09-10-2 Security Update 2009-005 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Debian -- Security Information -- DSA-1789-1 php5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:012 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-04-15 | Tomas Hoger | This issue did not affect PHP versions as shipped in Red Hat Enterprise Linux 2.1, 3, 4, and 5, and Red Hat Application Stack v1. PHP version in Red Hat Application Stack v2 was fixed via: https://rhn.redhat.com/errata/RHSA-2009-0350.html |
There are currently no legacy QID mappings associated with this CVE.