REDHAT-BUG-656917: Low severity PHP PHP IMAP extension vulnerability
Mateusz Kocielski reported a deficiency in the way PHP IMAP extension processed provided user credentials, when opening user mailbox folder. A local attacker could use this flaw to cause a denial of service (particular php application crash) or, potentially, execute arbitrary code with the privileges of the user running the application, by providing a specially-crafted user credentials.
References: [1] http://svn.php.net/viewvc?view=revision&revision=305062 [2] http://svn.php.net/viewvc/php/php-src/branches/PHP52/ext/imap/phpimap.c?r1=294699&r2=305032&pathrev=305032&view=patch [3] http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:239 [4] http://www.vupen.com/english/advisories/2010/3027
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-656917?
The severity of REDHAT-BUG-656917 is classified as a vulnerability that could lead to denial of service and potentially remote code execution.
How do I fix REDHAT-BUG-656917?
To fix REDHAT-BUG-656917, it is recommended to update the PHP IMAP extension to the latest version that addresses this vulnerability.
What type of attack is associated with REDHAT-BUG-656917?
REDHAT-BUG-656917 is associated with local attacks that could result in a denial of service and may lead to arbitrary code execution.
Who reported the vulnerability REDHAT-BUG-656917?
The vulnerability REDHAT-BUG-656917 was reported by Mateusz Kocielski.
Which software is affected by REDHAT-BUG-656917?
The affected software by REDHAT-BUG-656917 is the PHP IMAP extension.