The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Feb 14, 2012 |
| Php | — | Upgrade to PHP version 5.3.9 | Oct 1, 2012 | Feb 14, 2012 |
| Suse | — | Upgrade php53-zlibUpgrade php53-develUpgrade php53-domUpgrade php53-iconvUpgrade php53-sysvmsgUpgrade php53-gdUpgrade php53-calendarUpgrade php53-socketsUpgrade php53-zipUpgrade php53-soapUpgrade php53-suhosinUpgrade php53-sqliteUpgrade php53-sysvsemUpgrade php53-tidyUpgrade php53-ctypeUpgrade apache2-mod_php53Upgrade php53-shmopUpgrade php53-odbcUpgrade php53-mbstringUpgrade php53-pcntlUpgrade php53-fileinfoUpgrade php53-mcryptUpgrade php53-xmlwriterUpgrade php53Upgrade php53-readlineUpgrade php53-imapUpgrade php53-pspellUpgrade php53-jsonUpgrade php53-posixUpgrade php53-bz2Upgrade php53-bcmathUpgrade php53-tokenizerUpgrade php53-wddxUpgrade php53-dbaUpgrade php53-pgsqlUpgrade php53-exifUpgrade php53-ftpUpgrade php53-gmpUpgrade php53-pdoUpgrade php53-xslUpgrade php53-pearUpgrade php53-intlUpgrade php53-snmpUpgrade php53-xmlrpcUpgrade php53-opensslUpgrade php53-fastcgiUpgrade php53-gettextUpgrade php53-ldapUpgrade php53-mysqlUpgrade php53-xmlreaderUpgrade php53-sysvshmUpgrade php53-curl | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade php5-cliUpgrade libapache2-mod-php5Upgrade php5-commonUpgrade php5-xslUpgrade php5Upgrade php5-cgi | Nov 8, 2024 | Feb 14, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub