CVE-2002-2309: High severity PHP PHP vulnerability
Published Dec 31, 2002
·Updated
php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
Affected Software
38 affected components
PHP PHP=3.0.5
PHP PHP=3.0.11
PHP PHP=4.2.0
PHP PHP=3.0.1
PHP PHP=3.0.2
PHP PHP=4.1.0
PHP PHP=4.0.4
PHP PHP=4.0.5
PHP PHP=3.0.8
PHP PHP=3.0.13
PHP PHP=4.0.7-rc2
PHP PHP=4.0.7-rc1
PHP PHP=4.2.2
PHP PHP=3.0.7
PHP PHP=3.0.6
PHP PHP=4.0.3-patch1
PHP PHP=3.0.17
PHP PHP=4.0.7
PHP PHP=4.0.2
PHP PHP=4.1.1
PHP PHP=3.0.15
PHP PHP=3.0.16
PHP PHP=3.0.10
PHP PHP=3.0.4
PHP PHP=4.0.1-patch1
PHP PHP=4.0
PHP PHP=4.0.1-patch2
PHP PHP=4.0.6
PHP PHP=4.1.2
PHP PHP=4.0.7-rc3
PHP PHP=3.0.18
PHP PHP=4.2.1
PHP PHP=4.0.1
PHP PHP=3.0.12
PHP PHP=4.0.3
PHP PHP=3.0.14
PHP PHP=3.0.9
PHP PHP=3.0.3
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 26, 2007
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2309?
CVE-2002-2309 has been classified as a low severity vulnerability that allows denial of service.
2
How do I fix CVE-2002-2309?
To fix CVE-2002-2309, upgrade to a newer version of PHP that is not affected by this vulnerability.
3
What versions of PHP are affected by CVE-2002-2309?
CVE-2002-2309 affects PHP versions 3.0 through 4.2.2 when running on Apache.
4
Can CVE-2002-2309 be exploited remotely?
Yes, CVE-2002-2309 can be exploited remotely by sending a direct request to the php.exe without arguments.
5
What type of attack does CVE-2002-2309 facilitate?
CVE-2002-2309 facilitates denial of service attacks by causing the php.exe to not terminate properly.