CVE-2010-2950: Medium severity PHP PHP vulnerability
Format string vulnerability in stream.c in the phar extension in PHP 5.3.x through 5.3.3 allows context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the pharstreamflush function, leading to errors in the phpstreamwrapperlogerror function. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2094.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2950?
CVE-2010-2950 has a medium severity rating as it allows attackers to obtain sensitive information and potentially execute arbitrary code.
How do I fix CVE-2010-2950?
To fix CVE-2010-2950, upgrade to PHP version 5.3.4 or later, where this vulnerability has been addressed.
What software versions are affected by CVE-2010-2950?
CVE-2010-2950 affects PHP versions 5.3.0 to 5.3.3.
What type of vulnerability is CVE-2010-2950?
CVE-2010-2950 is a format string vulnerability found in the phar extension of PHP.
What are the potential impacts of CVE-2010-2950?
The potential impacts of CVE-2010-2950 include exposure of sensitive memory contents and the possibility of arbitrary code execution.