CVE-2010-3709: Input Validation
Published Nov 8, 2010
·Updated
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.
Affected Software
7 affected components
PHP PHP>=5.3.0<5.3.4
PHP PHP>=5.2.0<5.2.15
Ubuntu=10.10
Ubuntu=9.10
Ubuntu=8.04
Ubuntu=10.04
Ubuntu=6.06
Remediation
Event History
Nov 8, 2010
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3709?
CVE-2010-3709 has a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2010-3709?
To fix CVE-2010-3709, update your PHP version to 5.2.15 or later, or 5.3.4 or later.
3
Which versions of PHP are affected by CVE-2010-3709?
CVE-2010-3709 affects PHP versions 5.2.x up to 5.2.14 and 5.3.x up to 5.3.3.
4
Can CVE-2010-3709 affect Ubuntu Linux systems?
Yes, CVE-2010-3709 can affect Ubuntu Linux versions 6.06, 8.04, 9.10, 10.04, and 10.10.
5
What is a practical implication of CVE-2010-3709?
The practical implication of CVE-2010-3709 is that an attacker may craft a malicious ZIP archive, resulting in an application crash.