CVE-2010-4150 Information

Share on:

Description

Double free vulnerability in the imap_do_open function in the IMAP extension (ext/imap/php_imap.c) in PHP 5.2 before 5.2.15 and 5.3 before 5.3.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

Reference

http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052836.html http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052845.html http://marc.info/?l=bugtraq&m=133469208622507&w=2 http://secunia.com/advisories/42729 http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.490619 http://support.apple.com/kb/HT4581 http://svn.php.net/viewvc?view=revision&revision=305032 http://www.mandriva.com/security/advisories?name=MDVSA-2010:239 http://www.php.net/archive/2010.phpid2010-12-10-1 http://www.php.net/ChangeLog-5.php http://www.php.net/releases/5_2_15.php http://www.php.net/releases/5_3_4.php http://www.securityfocus.com/bid/44980 http://www.securitytracker.com/id?1024761 http://www.vupen.com/english/advisories/2010/3027 http://www.vupen.com/english/advisories/2010/3313 http://www.vupen.com/english/advisories/2011/0020 http://www.vupen.com/english/advisories/2011/0021 https://bugzilla.redhat.com/show_bug.cgi?id=656917 https://exchange.xforce.ibmcloud.com/vulnerabilities/63390 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A12489