oss-sec mailing list archives

CVE assignment php NULL pointer dereference - CVE-2011-3182


From: Josh Bressers <bressers () redhat com>
Date: Mon, 22 Aug 2011 14:39:32 -0400 (EDT)

This message was sent to the full-disclosure mailing list:
http://marc.info/?l=full-disclosure&m=131373057621672&w=2

From what I can tell, this is a plausible problem. The advisory doesn't
show any specific places where this could be exploited, but there are quite
a few unchecked calls to malloc(). Rather than go through them all, I'm
assigning the ID CVE-2011-3182 to be safe.

Thanks.

-- 
    JB


Current thread: