PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed.
References
Link | Resource |
---|---|
http://www.cert.org/advisories/CA-2002-21.html | US Government Resource |
http://www.kb.cert.org/vuls/id/929115 | US Government Resource |
http://www.iss.net/security_center/static/9635.php | |
http://marc.info/?l=bugtraq&m=102734515923277&w=2 | |
http://marc.info/?l=bugtraq&m=102734516023281&w=2 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-07-25 21:00
Updated : 2016-10-17 19:21
NVD link : CVE-2002-0717
Mitre link : CVE-2002-0717
JSON object : View
CWE
Products Affected
php
- php