CVE-2010-2531
Summary
| CVE | CVE-2010-2531 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-08-20 22:00:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the application to exceed limits for memory, execution time, or recursion. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About the security content of Mac OS X v10.6.5 and Security Update 2010-007 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| APPLE-SA-2010-11-10-1 Mac OS X v10.6.5 and Security Update 2010-007 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:018 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-2266-1 php5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| APPLE-SA-2010-08-24-1 Security Update 2010-005 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| PHP: News Archive - 2010 | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | Vendor Advisory |
| About Security Update 2010-005 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| Red Hat update for php - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| PHP: Log of /php/php-src/trunk/ext/standard/tests/general_functions/var_export_error2.phpt | af854a3a-2127-422b-91ae-364da2661108 | svn.php.net | Vendor Advisory |
| PHP: News Archive - 2010 | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| oss-security - CVE request, php var_export | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| Bug 617673 – CVE-2010-2531 php: information leak vulnerability in var_export() | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| oss-security - Re: Re: CVE request, php var_export | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| '[security bulletin] HPSBOV02763 SSRT100826 rev.1 - HP Secure Web Server (SWS) for OpenVMS running PH' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List, Third Party Advisory |
| '[security bulletin] HPSBMA02662 SSRT100409 rev.1 - HP System Management Homepage (SMH) for Linux and' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.