The (1) ZipArchive::addGlob and (2) ZipArchive::addPattern functions in ext/zip/php_zip.c in PHP 5.3.6 allow context-dependent attackers to cause a denial of service (application crash) via certain flags arguments, as demonstrated by (a) GLOB_ALTDIRFUNC and (b) GLOB_APPEND.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Addressbook | — | Upgrade macOS to the latest versionApply OS X security update 2012-001 | Aug 28, 2015 | Aug 25, 2011 |
| Apple Osx Php | — | Apply OS X security update 2012-001Upgrade macOS to the latest version | Feb 3, 2012 | Aug 25, 2011 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Aug 25, 2011 |
| Php | — | Upgrade to PHP version 5.3.7 | Oct 1, 2012 | Aug 25, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 7, 2011 |
| Ubuntu | — | Upgrade php5-commonUpgrade php5-cliUpgrade php5-cgiUpgrade libapache2-mod-php5 | Nov 8, 2024 | Aug 25, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub