CVE-2011-3379
Summary
| CVE | CVE-2011-3379 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-11-03 15:55:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHP: Revision 317183 | af854a3a-2127-422b-91ae-364da2661108 | svn.php.net | Patch |
| HPSBMU02786 SSRT100877 rev.2 - HP System Management Homepage (SMH) Running on Linux, Windows, and VMware ESX, Remote Unauthorized Access, Disclosure of Information, Data Modification, Denial of Service (DoS), Execution of Arbitrary Code - c03360041 - HP Business Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| PHP 5.3.7+ issue is_a function - SecurityReason.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| PHP :: Bug #55475 :: is_a() triggers autoloader | af854a3a-2127-422b-91ae-364da2661108 | bugs.php.net | Exploit |
| Bug 741020 – CVE-2011-3379 php: changes to is_a() in 5.3.7 may allow arbitrary code execution with certain code | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| Security bug in is_a function in PHP 5.3.7 / 5.3.8 | af854a3a-2127-422b-91ae-364da2661108 | www.byte.nl | Exploit |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.