The (1) ZipArchive::addGlob and (2) ZipArchive::addPattern functions in ext/zip/php_zip.c in PHP 5.3.6 allow context-dependent attackers to cause a denial of service (application crash) via certain flags arguments, as demonstrated by (a) GLOB_ALTDIRFUNC and (b) GLOB_APPEND.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Addressbook | — | Upgrade macOS to the latest versionApply OS X security update 2012-001 | Aug 28, 2015 | Aug 25, 2011 |
| Apple Osx Php | — | Upgrade macOS to the latest versionApply OS X security update 2012-001 | Feb 3, 2012 | Aug 25, 2011 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Aug 25, 2011 |
| Php | — | Upgrade to PHP version 5.3.7 | Oct 1, 2012 | Aug 25, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 7, 2011 |
| Ubuntu | — | Upgrade php5-commonUpgrade php5-cliUpgrade libapache2-mod-php5Upgrade php5-cgi | Nov 8, 2024 | Aug 25, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub