SB2013071603 - Buffer overflow in php (Alpine package)
Published: July 16, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Buffer overflow (CVE-ID: CVE-2013-4113)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=1a8b152e8a88f0dbf4b4041048286b6c17476061
- https://git.alpinelinux.org/aports/commit/?id=557e3af1ace8b185c2831c4ebe37fc8c5326c189
- https://git.alpinelinux.org/aports/commit/?id=1be6dba9064c72276b4cebc2a9ade9b279d90d84
- https://git.alpinelinux.org/aports/commit/?id=805bb44105b1f929aabd924795f9b6280fc50f82