Rapid7 VulnDB

SUSE Linux Security Advisory: SUSE-SR:2010:017

Back to Search

SUSE Linux Security Advisory: SUSE-SR:2010:017

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
06/24/2010
Created
07/25/2018
Added
12/12/2013
Modified
07/04/2017

Description

Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.

Solution(s)

  • suse-upgrade-apache-jakarta-tomcat-connectors
  • suse-upgrade-apache2-jakarta-tomcat-connectors
  • suse-upgrade-apache2-mod_php5
  • suse-upgrade-aria2
  • suse-upgrade-dovecot12
  • suse-upgrade-dovecot12-backend-mysql
  • suse-upgrade-dovecot12-backend-pgsql
  • suse-upgrade-dovecot12-backend-sqlite
  • suse-upgrade-dovecot12-devel
  • suse-upgrade-dovecot12-fts-lucene
  • suse-upgrade-dovecot12-fts-solr
  • suse-upgrade-ibmjava2-jre
  • suse-upgrade-ibmjava2-sdk
  • suse-upgrade-ibmjava5-jre
  • suse-upgrade-ibmjava5-sdk
  • suse-upgrade-iscsitarget
  • suse-upgrade-iscsitarget-kmp-debug
  • suse-upgrade-iscsitarget-kmp-default
  • suse-upgrade-iscsitarget-kmp-desktop
  • suse-upgrade-iscsitarget-kmp-pae
  • suse-upgrade-iscsitarget-kmp-ppc64
  • suse-upgrade-iscsitarget-kmp-trace
  • suse-upgrade-iscsitarget-kmp-vmi
  • suse-upgrade-iscsitarget-kmp-xen
  • suse-upgrade-jakarta-tomcat
  • suse-upgrade-jakarta-tomcat-doc
  • suse-upgrade-jakarta-tomcat-examples
  • suse-upgrade-java-1_4_2-ibm
  • suse-upgrade-java-1_4_2-ibm-devel
  • suse-upgrade-java-1_4_2-ibm-jdbc
  • suse-upgrade-java-1_4_2-ibm-plugin
  • suse-upgrade-java-1_5_0-ibm
  • suse-upgrade-java-1_5_0-ibm-32bit
  • suse-upgrade-java-1_5_0-ibm-64bit
  • suse-upgrade-java-1_5_0-ibm-alsa
  • suse-upgrade-java-1_5_0-ibm-alsa-32bit
  • suse-upgrade-java-1_5_0-ibm-demo
  • suse-upgrade-java-1_5_0-ibm-devel
  • suse-upgrade-java-1_5_0-ibm-devel-32bit
  • suse-upgrade-java-1_5_0-ibm-fonts
  • suse-upgrade-java-1_5_0-ibm-jdbc
  • suse-upgrade-java-1_5_0-ibm-plugin
  • suse-upgrade-java-1_5_0-ibm-src
  • suse-upgrade-java-1_6_0-ibm
  • suse-upgrade-java-1_6_0-ibm-alsa
  • suse-upgrade-java-1_6_0-ibm-fonts
  • suse-upgrade-java-1_6_0-ibm-jdbc
  • suse-upgrade-java-1_6_0-ibm-plugin
  • suse-upgrade-java-1_6_0-openjdk
  • suse-upgrade-java-1_6_0-openjdk-demo
  • suse-upgrade-java-1_6_0-openjdk-devel
  • suse-upgrade-java-1_6_0-openjdk-javadoc
  • suse-upgrade-java-1_6_0-openjdk-plugin
  • suse-upgrade-java-1_6_0-openjdk-src
  • suse-upgrade-java-1_6_0-sun
  • suse-upgrade-java-1_6_0-sun-alsa
  • suse-upgrade-java-1_6_0-sun-demo
  • suse-upgrade-java-1_6_0-sun-devel
  • suse-upgrade-java-1_6_0-sun-jdbc
  • suse-upgrade-java-1_6_0-sun-plugin
  • suse-upgrade-java-1_6_0-sun-src
  • suse-upgrade-libpcsclite1
  • suse-upgrade-libpcsclite1-32bit
  • suse-upgrade-libpng
  • suse-upgrade-libpng-32bit
  • suse-upgrade-libpng-64bit
  • suse-upgrade-libpng-devel
  • suse-upgrade-libpng-devel-32bit
  • suse-upgrade-libpng-devel-64bit
  • suse-upgrade-libpng-x86
  • suse-upgrade-libpng12-0
  • suse-upgrade-libpng12-0-32bit
  • suse-upgrade-libpng12-0-64bit
  • suse-upgrade-libpng12-0-x86
  • suse-upgrade-libpng3
  • suse-upgrade-libtiff-devel
  • suse-upgrade-libtiff-devel-32bit
  • suse-upgrade-libtiff3
  • suse-upgrade-libtiff3-32bit
  • suse-upgrade-libvirt
  • suse-upgrade-libvirt-client
  • suse-upgrade-libvirt-devel
  • suse-upgrade-libvirt-doc
  • suse-upgrade-libvirt-python
  • suse-upgrade-lvm2
  • suse-upgrade-lvm2-clvm
  • suse-upgrade-mozilla-xulrunner191
  • suse-upgrade-mozilla-xulrunner191-32bit
  • suse-upgrade-mozilla-xulrunner191-devel
  • suse-upgrade-mozilla-xulrunner191-gnomevfs
  • suse-upgrade-mozilla-xulrunner191-gnomevfs-32bit
  • suse-upgrade-mozilla-xulrunner191-translations-common
  • suse-upgrade-mozilla-xulrunner191-translations-other
  • suse-upgrade-mozillafirefox
  • suse-upgrade-mozillafirefox-branding-upstream
  • suse-upgrade-mozillafirefox-translations-common
  • suse-upgrade-mozillafirefox-translations-other
  • suse-upgrade-pcsc-lite
  • suse-upgrade-pcsc-lite-32bit
  • suse-upgrade-pcsc-lite-devel
  • suse-upgrade-pcsc-lite-x86
  • suse-upgrade-php5-bcmath
  • suse-upgrade-php5-bz2
  • suse-upgrade-php5-calendar
  • suse-upgrade-php5-ctype
  • suse-upgrade-php5-curl
  • suse-upgrade-php5-dba
  • suse-upgrade-php5-dbase
  • suse-upgrade-php5-devel
  • suse-upgrade-php5-dom
  • suse-upgrade-php5-enchant
  • suse-upgrade-php5-exif
  • suse-upgrade-php5-fastcgi
  • suse-upgrade-php5-fileinfo
  • suse-upgrade-php5-ftp
  • suse-upgrade-php5-gd
  • suse-upgrade-php5-gettext
  • suse-upgrade-php5-gmp
  • suse-upgrade-php5-hash
  • suse-upgrade-php5-iconv
  • suse-upgrade-php5-imap
  • suse-upgrade-php5-intl
  • suse-upgrade-php5-json
  • suse-upgrade-php5-ldap
  • suse-upgrade-php5-mbstring
  • suse-upgrade-php5-mcrypt
  • suse-upgrade-php5-mhash
  • suse-upgrade-php5-mysql
  • suse-upgrade-php5-ncurses
  • suse-upgrade-php5-odbc
  • suse-upgrade-php5-openssl
  • suse-upgrade-php5-pcntl
  • suse-upgrade-php5-pdo
  • suse-upgrade-php5-pear
  • suse-upgrade-php5-pgsql
  • suse-upgrade-php5-phar
  • suse-upgrade-php5-posix
  • suse-upgrade-php5-pspell
  • suse-upgrade-php5-readline
  • suse-upgrade-php5-shmop
  • suse-upgrade-php5-snmp
  • suse-upgrade-php5-soap
  • suse-upgrade-php5-sockets
  • suse-upgrade-php5-sqlite
  • suse-upgrade-php5-suhosin
  • suse-upgrade-php5-sysvmsg
  • suse-upgrade-php5-sysvsem
  • suse-upgrade-php5-sysvshm
  • suse-upgrade-php5-tidy
  • suse-upgrade-php5-tokenizer
  • suse-upgrade-php5-wddx
  • suse-upgrade-php5-xmlreader
  • suse-upgrade-php5-xmlrpc
  • suse-upgrade-php5-xmlwriter
  • suse-upgrade-php5-xsl
  • suse-upgrade-php5-zip
  • suse-upgrade-php5-zlib
  • suse-upgrade-popt
  • suse-upgrade-popt-32bit
  • suse-upgrade-popt-64bit
  • suse-upgrade-popt-devel
  • suse-upgrade-popt-devel-32bit
  • suse-upgrade-popt-devel-64bit
  • suse-upgrade-popt-x86
  • suse-upgrade-python-xpcom191
  • suse-upgrade-rpm
  • suse-upgrade-rpm-32bit
  • suse-upgrade-rpm-64bit
  • suse-upgrade-rpm-devel
  • suse-upgrade-rpm-devel-static
  • suse-upgrade-rpm-python
  • suse-upgrade-rpm-x86
  • suse-upgrade-sap-aio-release
  • suse-upgrade-sles-for-vmware-release
  • suse-upgrade-sudo
  • suse-upgrade-tgt
  • suse-upgrade-tiff
  • suse-upgrade-tomcat5
  • suse-upgrade-tomcat5-admin-webapps
  • suse-upgrade-tomcat5-webapps
  • suse-upgrade-tomcat6
  • suse-upgrade-tomcat6-admin-webapps
  • suse-upgrade-tomcat6-docs-webapp
  • suse-upgrade-tomcat6-el-1_0-api
  • suse-upgrade-tomcat6-javadoc
  • suse-upgrade-tomcat6-jsp-2_1-api
  • suse-upgrade-tomcat6-lib
  • suse-upgrade-tomcat6-servlet-2_5-api
  • suse-upgrade-tomcat6-webapps

References

  • suse-upgrade-apache-jakarta-tomcat-connectors
  • suse-upgrade-apache2-jakarta-tomcat-connectors
  • suse-upgrade-apache2-mod_php5
  • suse-upgrade-aria2
  • suse-upgrade-dovecot12
  • suse-upgrade-dovecot12-backend-mysql
  • suse-upgrade-dovecot12-backend-pgsql
  • suse-upgrade-dovecot12-backend-sqlite
  • suse-upgrade-dovecot12-devel
  • suse-upgrade-dovecot12-fts-lucene
  • suse-upgrade-dovecot12-fts-solr
  • suse-upgrade-ibmjava2-jre
  • suse-upgrade-ibmjava2-sdk
  • suse-upgrade-ibmjava5-jre
  • suse-upgrade-ibmjava5-sdk
  • suse-upgrade-iscsitarget
  • suse-upgrade-iscsitarget-kmp-debug
  • suse-upgrade-iscsitarget-kmp-default
  • suse-upgrade-iscsitarget-kmp-desktop
  • suse-upgrade-iscsitarget-kmp-pae
  • suse-upgrade-iscsitarget-kmp-ppc64
  • suse-upgrade-iscsitarget-kmp-trace
  • suse-upgrade-iscsitarget-kmp-vmi
  • suse-upgrade-iscsitarget-kmp-xen
  • suse-upgrade-jakarta-tomcat
  • suse-upgrade-jakarta-tomcat-doc
  • suse-upgrade-jakarta-tomcat-examples
  • suse-upgrade-java-1_4_2-ibm
  • suse-upgrade-java-1_4_2-ibm-devel
  • suse-upgrade-java-1_4_2-ibm-jdbc
  • suse-upgrade-java-1_4_2-ibm-plugin
  • suse-upgrade-java-1_5_0-ibm
  • suse-upgrade-java-1_5_0-ibm-32bit
  • suse-upgrade-java-1_5_0-ibm-64bit
  • suse-upgrade-java-1_5_0-ibm-alsa
  • suse-upgrade-java-1_5_0-ibm-alsa-32bit
  • suse-upgrade-java-1_5_0-ibm-demo
  • suse-upgrade-java-1_5_0-ibm-devel
  • suse-upgrade-java-1_5_0-ibm-devel-32bit
  • suse-upgrade-java-1_5_0-ibm-fonts
  • suse-upgrade-java-1_5_0-ibm-jdbc
  • suse-upgrade-java-1_5_0-ibm-plugin
  • suse-upgrade-java-1_5_0-ibm-src
  • suse-upgrade-java-1_6_0-ibm
  • suse-upgrade-java-1_6_0-ibm-alsa
  • suse-upgrade-java-1_6_0-ibm-fonts
  • suse-upgrade-java-1_6_0-ibm-jdbc
  • suse-upgrade-java-1_6_0-ibm-plugin
  • suse-upgrade-java-1_6_0-openjdk
  • suse-upgrade-java-1_6_0-openjdk-demo
  • suse-upgrade-java-1_6_0-openjdk-devel
  • suse-upgrade-java-1_6_0-openjdk-javadoc
  • suse-upgrade-java-1_6_0-openjdk-plugin
  • suse-upgrade-java-1_6_0-openjdk-src
  • suse-upgrade-java-1_6_0-sun
  • suse-upgrade-java-1_6_0-sun-alsa
  • suse-upgrade-java-1_6_0-sun-demo
  • suse-upgrade-java-1_6_0-sun-devel
  • suse-upgrade-java-1_6_0-sun-jdbc
  • suse-upgrade-java-1_6_0-sun-plugin
  • suse-upgrade-java-1_6_0-sun-src
  • suse-upgrade-libpcsclite1
  • suse-upgrade-libpcsclite1-32bit
  • suse-upgrade-libpng
  • suse-upgrade-libpng-32bit
  • suse-upgrade-libpng-64bit
  • suse-upgrade-libpng-devel
  • suse-upgrade-libpng-devel-32bit
  • suse-upgrade-libpng-devel-64bit
  • suse-upgrade-libpng-x86
  • suse-upgrade-libpng12-0
  • suse-upgrade-libpng12-0-32bit
  • suse-upgrade-libpng12-0-64bit
  • suse-upgrade-libpng12-0-x86
  • suse-upgrade-libpng3
  • suse-upgrade-libtiff-devel
  • suse-upgrade-libtiff-devel-32bit
  • suse-upgrade-libtiff3
  • suse-upgrade-libtiff3-32bit
  • suse-upgrade-libvirt
  • suse-upgrade-libvirt-client
  • suse-upgrade-libvirt-devel
  • suse-upgrade-libvirt-doc
  • suse-upgrade-libvirt-python
  • suse-upgrade-lvm2
  • suse-upgrade-lvm2-clvm
  • suse-upgrade-mozilla-xulrunner191
  • suse-upgrade-mozilla-xulrunner191-32bit
  • suse-upgrade-mozilla-xulrunner191-devel
  • suse-upgrade-mozilla-xulrunner191-gnomevfs
  • suse-upgrade-mozilla-xulrunner191-gnomevfs-32bit
  • suse-upgrade-mozilla-xulrunner191-translations-common
  • suse-upgrade-mozilla-xulrunner191-translations-other
  • suse-upgrade-mozillafirefox
  • suse-upgrade-mozillafirefox-branding-upstream
  • suse-upgrade-mozillafirefox-translations-common
  • suse-upgrade-mozillafirefox-translations-other
  • suse-upgrade-pcsc-lite
  • suse-upgrade-pcsc-lite-32bit
  • suse-upgrade-pcsc-lite-devel
  • suse-upgrade-pcsc-lite-x86
  • suse-upgrade-php5-bcmath
  • suse-upgrade-php5-bz2
  • suse-upgrade-php5-calendar
  • suse-upgrade-php5-ctype
  • suse-upgrade-php5-curl
  • suse-upgrade-php5-dba
  • suse-upgrade-php5-dbase
  • suse-upgrade-php5-devel
  • suse-upgrade-php5-dom
  • suse-upgrade-php5-enchant
  • suse-upgrade-php5-exif
  • suse-upgrade-php5-fastcgi
  • suse-upgrade-php5-fileinfo
  • suse-upgrade-php5-ftp
  • suse-upgrade-php5-gd
  • suse-upgrade-php5-gettext
  • suse-upgrade-php5-gmp
  • suse-upgrade-php5-hash
  • suse-upgrade-php5-iconv
  • suse-upgrade-php5-imap
  • suse-upgrade-php5-intl
  • suse-upgrade-php5-json
  • suse-upgrade-php5-ldap
  • suse-upgrade-php5-mbstring
  • suse-upgrade-php5-mcrypt
  • suse-upgrade-php5-mhash
  • suse-upgrade-php5-mysql
  • suse-upgrade-php5-ncurses
  • suse-upgrade-php5-odbc
  • suse-upgrade-php5-openssl
  • suse-upgrade-php5-pcntl
  • suse-upgrade-php5-pdo
  • suse-upgrade-php5-pear
  • suse-upgrade-php5-pgsql
  • suse-upgrade-php5-phar
  • suse-upgrade-php5-posix
  • suse-upgrade-php5-pspell
  • suse-upgrade-php5-readline
  • suse-upgrade-php5-shmop
  • suse-upgrade-php5-snmp
  • suse-upgrade-php5-soap
  • suse-upgrade-php5-sockets
  • suse-upgrade-php5-sqlite
  • suse-upgrade-php5-suhosin
  • suse-upgrade-php5-sysvmsg
  • suse-upgrade-php5-sysvsem
  • suse-upgrade-php5-sysvshm
  • suse-upgrade-php5-tidy
  • suse-upgrade-php5-tokenizer
  • suse-upgrade-php5-wddx
  • suse-upgrade-php5-xmlreader
  • suse-upgrade-php5-xmlrpc
  • suse-upgrade-php5-xmlwriter
  • suse-upgrade-php5-xsl
  • suse-upgrade-php5-zip
  • suse-upgrade-php5-zlib
  • suse-upgrade-popt
  • suse-upgrade-popt-32bit
  • suse-upgrade-popt-64bit
  • suse-upgrade-popt-devel
  • suse-upgrade-popt-devel-32bit
  • suse-upgrade-popt-devel-64bit
  • suse-upgrade-popt-x86
  • suse-upgrade-python-xpcom191
  • suse-upgrade-rpm
  • suse-upgrade-rpm-32bit
  • suse-upgrade-rpm-64bit
  • suse-upgrade-rpm-devel
  • suse-upgrade-rpm-devel-static
  • suse-upgrade-rpm-python
  • suse-upgrade-rpm-x86
  • suse-upgrade-sap-aio-release
  • suse-upgrade-sles-for-vmware-release
  • suse-upgrade-sudo
  • suse-upgrade-tgt
  • suse-upgrade-tiff
  • suse-upgrade-tomcat5
  • suse-upgrade-tomcat5-admin-webapps
  • suse-upgrade-tomcat5-webapps
  • suse-upgrade-tomcat6
  • suse-upgrade-tomcat6-admin-webapps
  • suse-upgrade-tomcat6-docs-webapp
  • suse-upgrade-tomcat6-el-1_0-api
  • suse-upgrade-tomcat6-javadoc
  • suse-upgrade-tomcat6-jsp-2_1-api
  • suse-upgrade-tomcat6-lib
  • suse-upgrade-tomcat6-servlet-2_5-api
  • suse-upgrade-tomcat6-webapps

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;