OS X update for PHP (CVE-2013-4113)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:M/Au:N/C:P/I:P/A:P) | July 13, 2013 | March 03, 2014 | April 05, 2017 |
Description
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
Free Nexpose Download
Discover, prioritize, and remediate security risks today!
References
Solution
apple-osx-security-update-2014-001Related Vulnerabilities
- PHP Vulnerability: CVE-2013-4113
- RHSA-2013:1050: php53 security update
- ELSA-2013-1049 Critical: Oracle Linux php security update
- RHSA-2013:1062: php53 security update
- USN-1905-1: PHP vulnerabilities
- Oracle Solaris 11: CVE-2013-4113: Vulnerability in PHP
- FreeBSD: PHP5 -- Heap corruption in XML parser (CVE-2013-4113)
- OS X update for Apache (CVE-2013-4113)
- Vulnerabilities deemed not relevant on Red Hat Enterprise Linux 5
- Vulnerabilities deemed not relevant on Red Hat Enterprise Linux 7
- Gentoo Linux: CVE-2013-4113: PHP: Multiple vulnerabilities
- ELSA-2013-1063 Critical: Oracle Linux php security update
- Amazon Linux AMI: Security patch for php54 (ALAS-2013-212) (CVE-2013-4113)
- ELSA-2013-1307 Moderate: Oracle Linux php53 security, bug fix and enhancement update
- RHSA-2013:1061: php security update
- Vulnerabilities deemed not relevant on Red Hat Enterprise Linux 4
- Juniper Junos OS: 2017-07 Security Bulletin: Junos OS: J-Web: Multiple Vulnerabilities in PHP software (JSA10804) (multiple CVEs)
- RHSA-2013:1049: php security update
- Alpine Linux: CVE-2013-4113: CVE-2013-4113 php xml_parse_into_struct buffer overflow when parsing deeply nested XML
- DSA-2723-1 php5 -- heap corruption
- SUSE Linux Security Vulnerability: CVE-2013-4113
- Amazon Linux AMI: Security patch for php (ALAS-2013-211) (CVE-2013-4113)
- Vulnerabilities deemed not relevant on Red Hat Enterprise Linux 3
- Vulnerabilities deemed not relevant on Red Hat Enterprise Linux 6
- ELSA-2013-1050 Critical: Oracle Linux php53 security update
- RHSA-2013:1063: php security update