PHP 'tidy_diagnose()' NULL Pointer Dereference Denial Of Service Vulnerability
BID:51992
Info
PHP 'tidy_diagnose()' NULL Pointer Dereference Denial Of Service Vulnerability
| Bugtraq ID: | 51992 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2012-0781 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2012 12:00AM |
| Updated: | Nov 14 2014 12:01AM |
| Credit: | Maksymilian Arciemowicz |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server for VMware 11 SP1 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise SDK 10 SP4 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 PHP PHP 5.3.8 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
PHP 'tidy_diagnose()' NULL Pointer Dereference Denial Of Service Vulnerability
PHP is prone to a denial-of-service vulnerability caused by a NULL-pointer dereference.
An attacker can exploit this issue to cause an application written in PHP to crash, denying service to legitimate users.
PHP 5.3.8 is vulnerable; other versions may also be affected.
PHP is prone to a denial-of-service vulnerability caused by a NULL-pointer dereference.
An attacker can exploit this issue to cause an application written in PHP to crash, denying service to legitimate users.
PHP 5.3.8 is vulnerable; other versions may also be affected.
Exploit / POC
PHP 'tidy_diagnose()' NULL Pointer Dereference Denial Of Service Vulnerability
An attacker can use readily available tools to exploit these issues.
An attacker can use readily available tools to exploit these issues.
Solution / Fix
PHP 'tidy_diagnose()' NULL Pointer Dereference Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
PHP 'tidy_diagnose()' NULL Pointer Dereference Denial Of Service Vulnerability
References:
References: