CVE-2006-1490
medium · 5PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.
5
CVSS
21.0%
EPSS (exploit prob.)
97th
EPSS percentile
2006-03-29
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| php | php | 3.0 |
| php | php | 3.0.1 |
| php | php | 3.0.2 |
| php | php | 3.0.3 |
| php | php | 3.0.4 |
| php | php | 3.0.5 |
| php | php | 3.0.6 |
| php | php | 3.0.7 |
| php | php | 3.0.8 |
| php | php | 3.0.9 |
| php | php | 3.0.10 |
| php | php | 3.0.11 |
| php | php | 3.0.12 |
| php | php | 3.0.13 |
| php | php | 3.0.14 |
| php | php | 3.0.15 |
| php | php | 3.0.16 |
| php | php | 3.0.17 |
| php | php | 3.0.18 |
| php | php | 4.0.0 |
| php | php | 4.0.1 |
| php | php | 4.0.1 |
| php | php | 4.0.1 |
| php | php | 4.0.2 |
| php | php | 4.0.3 |
| php | php | 4.0.3 |
| php | php | 4.0.4 |
| php | php | 4.0.5 |
| php | php | 4.0.6 |
| php | php | 4.0.7 |
| php | php | 4.0.7 |
| php | php | 4.0.7 |
| php | php | 4.0.7 |
| php | php | 4.1.0 |
| php | php | 4.1.1 |
| php | php | 4.1.2 |
| php | php | 4.2 |
| php | php | 4.2.0 |
| php | php | 4.2.1 |
| php | php | 4.2.2 |
Check a specific version with /api/v1/cve/match.
References
- ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc
- http://bugs.gentoo.org/show_bug.cgi?id=127939
- http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/html.c?r1=1.112&r2=1.113
- http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/html.c?view=log
- http://docs.info.apple.com/article.html?artnum=304829
- http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html
- http://rhn.redhat.com/errata/RHSA-2006-0276.html
- http://secunia.com/advisories/19383
- http://secunia.com/advisories/19499
- http://secunia.com/advisories/19570
- http://secunia.com/advisories/19832
- http://secunia.com/advisories/19979
- http://secunia.com/advisories/20052
- http://secunia.com/advisories/20210
- http://secunia.com/advisories/20951
- http://secunia.com/advisories/21125
- http://secunia.com/advisories/23155
- http://security.gentoo.org/glsa/glsa-200605-08.xml
- http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:063
- http://www.novell.com/linux/security/advisories/05-05-2006.html
- http://www.securityfocus.com/archive/1/429162/100/0/threaded
- http://www.securityfocus.com/archive/1/429164/100/0/threaded
- http://www.securityfocus.com/bid/17296
- http://www.trustix.org/errata/2006/0020
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-1490