CVE-2011-0421
Publication date 19 March 2011
Last updated 24 July 2024
Ubuntu priority
The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.
Status
Package | Ubuntu Release | Status |
---|---|---|
libzip | ||
php5 | ||
Notes
Patch details
Package | Patch details |
---|---|
libzip | |
php5 |
References
Related Ubuntu Security Notices (USN)
- USN-1126-1
- PHP vulnerabilities
- 29 April 2011