Skip to main content

PHP xml_parse_into_struct() Heap Overflow Vulnerability

Last Update Date: 16 Jul 2013 10:46 Release Date: 16 Jul 2013 3313 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

A vulnerability was reported in PHP. A remote user can execute arbitrary code on the target system.

 

A remote user can send specially crafted nested XML to trigger a heap overflow in xml_parse_into_struct() and execute arbitrary code on the target system. The code will run with the privileges of the target service.


Impact

  • Remote Code Execution

System / Technologies affected

  • PHP version 5.3 prior to 5.3.27

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link