CVE-2010-2100: Infoleak
The (1) htmlentities, (2) htmlspecialchars, (3) strgetcsv, (4) httpbuildquery, (5) strpbrk, and (6) strtr functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2100?
CVE-2010-2100 is classified as a moderate severity vulnerability.
How do I fix CVE-2010-2100?
To fix CVE-2010-2100, upgrade PHP to version 5.2.14 or higher, or 5.3.3 or higher.
What software versions are affected by CVE-2010-2100?
The affected PHP versions include 5.2.0 through 5.2.13 and 5.3.0 through 5.3.2.
What type of attack does CVE-2010-2100 involve?
CVE-2010-2100 allows context-dependent attackers to obtain sensitive information through userspace interruption.
Is CVE-2010-2100 exploitable remotely?
CVE-2010-2100 is not necessarily exploitable remotely as it depends on context-specific conditions.