Heap-based buffer overflow in the php_quot_print_encode function in ext/standard/quot_print.c in PHP before 5.3.26 and 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted argument to the quoted_printable_encode function.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Aug 28, 2015 | Jun 21, 2013 |
| Apple Osx Php | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Sep 17, 2013 | Jun 21, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 30, 2015 |
| Freebsd | — | Upgrade php5Upgrade php53 | Dec 10, 2025 | Jun 7, 2013 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Jun 21, 2013 |
| Oracle Solaris | — | Upgrade web/php-52 to version 5.2.17-0.175.1.17.0.3.0 on Solaris 11.1Upgrade web/php-53 to version 5.3.27-0.175.1.17.0.3.0 on Solaris 11.1 | May 29, 2017 | Jun 21, 2013 |
| Php | — | Upgrade to PHP version 5.3.26Upgrade to PHP version 5.4.16 | Jul 11, 2013 | Jun 21, 2013 |
| Ubuntu | — | Upgrade php5 | Nov 8, 2024 | Jun 21, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub