CVE-2010-2097: Infoleak
The (1) iconvmimedecode, (2) iconvsubstr, and (3) iconvmimeencode functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2097?
CVE-2010-2097 has been rated as having a medium severity due to potential information disclosure risks.
How do I fix CVE-2010-2097?
To fix CVE-2010-2097, upgrade your PHP installation to a version later than 5.3.2 or 5.2.13.
What versions of PHP are affected by CVE-2010-2097?
CVE-2010-2097 affects PHP versions in the 5.2.x series up to 5.2.13 and the 5.3.x series up to 5.3.2.
What kind of vulnerabilities does CVE-2010-2097 present?
CVE-2010-2097 presents a risk of sensitive information being disclosed due to a userspace interruption in internal function calls.
Who can exploit CVE-2010-2097?
Context-dependent attackers can exploit CVE-2010-2097 to obtain sensitive information if the vulnerable PHP functions are utilized.