Back to search

OS X update for PHP (CVE-2011-4885)

Severity CVSS Published Added Modified
5 (AV:N/AC:L/Au:N/C:N/I:N/A:P) December 29, 2011 July 16, 2012 August 28, 2013

Available Exploits 

Description

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Free Nexpose Download

Discover, prioritize, and remediate security risks today!

 Download now

References

Solution

  • Apple Mac OS X 10.6.8

    Apply OS X security update 2012-002

    Apply the necessary updates by selecting 'Software Update' from the Apple menu, or by using the softwareupdate utility

  • Apple Mac OS X >= 10.7 and < 10.7.4

    Upgrade to OS X version 10.7.4

    Apply the necessary updates by selecting 'Software Update' from the Apple menu, or by using the softwareupdate utility

Related Vulnerabilities