PHP xml_parse_into_struct() Heap Overflow Vulnerability
Last Update Date:
16 Jul 2013 10:46
Release Date:
16 Jul 2013
4242
Views
RISK: Medium Risk
TYPE: Servers - Internet App Servers

A vulnerability was reported in PHP. A remote user can execute arbitrary code on the target system.
A remote user can send specially crafted nested XML to trigger a heap overflow in xml_parse_into_struct() and execute arbitrary code on the target system. The code will run with the privileges of the target service.
Impact
- Remote Code Execution
System / Technologies affected
- PHP version 5.3 prior to 5.3.27
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (5.3.27).
http://php.net/archive/2013.php#id2013-07-11-1
Vulnerability Identifier
Source
Related Link
Share with