vendor:
PHP
by:
Not mentioned
5.5
CVSS
MEDIUM
Denial-of-Service
400
CWE
Product Name: PHP
Affected Version From: PHP versions prior to 5.3.6
Affected Version To: Not mentioned
Patch Exists: YES
Related CWE: CVE-2011-0421
CPE: a:php:php
Metasploit:
https://www.rapid7.com/db/vulnerabilities/suse-cve-2011-2501/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2011-2501/, https://www.rapid7.com/db/vulnerabilities/php-cve-2011-0421/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apache-cve-2011-0421/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2011-0421/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-fe853666-56ce-11e0-9668-001fd0d616cf/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2011-0421/, https://www.rapid7.com/db/vulnerabilities/apple-osx-php-cve-2011-0421/
Platforms Tested: Not mentioned
2011
Remote Denial-of-Service Vulnerability in PHP Zip Extension
The vulnerability affects the 'Zip' extension in PHP, allowing remote attackers to cause a denial-of-service condition by crashing the application. It may also be possible for attackers to execute arbitrary code, although this has not been confirmed.
Mitigation:
Update to PHP version 5.3.6 or later to fix this vulnerability.