CVE-2010-2094
Summary
| CVE | CVE-2010-2094 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-05-27 22:30:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the (1) phar_stream_flush, (2) phar_wrapper_unlink, (3) phar_parse_url, or (4) phar_wrapper_open_url functions in ext/phar/stream.c; and the (5) phar_wrapper_open_dir function in ext/phar/dirstream.c, which triggers errors in the php_stream_wrapper_log_error function. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:018 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| MOPS-2010-028: PHP phar_wrapper_open_url Format String Vulnerabilities « the Month of PHP Security | af854a3a-2127-422b-91ae-364da2661108 | php-security.org | Exploit |
| MOPS-2010-027: PHP phar_parse_url Format String Vulnerabilities « the Month of PHP Security | af854a3a-2127-422b-91ae-364da2661108 | php-security.org | Exploit |
| MOPS-2010-024: PHP phar_stream_flush Format String Vulnerability « the Month of PHP Security | af854a3a-2127-422b-91ae-364da2661108 | php-security.org | Exploit |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| MOPS-2010-026: PHP phar_wrapper_unlink Format String Vulnerability « the Month of PHP Security | af854a3a-2127-422b-91ae-364da2661108 | php-security.org | Exploit |
| Support / Security / Advisories / / MDVSA-2011:004 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| MOPS-2010-025: PHP phar_wrapper_open_dir Format String Vulnerability « the Month of PHP Security | af854a3a-2127-422b-91ae-364da2661108 | php-security.org | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.