The array_fill function in ext/standard/array.c in PHP 4.4.2 and 5.1.2 allows context-dependent attackers to cause a denial of service (memory consumption) via a large num value.
References
Link | Resource |
---|---|
http://www.infigo.hr/hr/in_focus/advisories/INFIGO-2006-04-02 | Exploit Vendor Advisory |
http://www.osvdb.org/24945 | |
http://securitytracker.com/id?1015979 | Exploit |
Configurations
Configuration 1 (hide)
|
Information
Published : 2007-05-23 19:30
Updated : 2008-09-05 14:16
NVD link : CVE-2006-7205
Mitre link : CVE-2006-7205
JSON object : View
CWE
Products Affected
php_group
- php