The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the application to exceed limits for memory, execution time, or recursion.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2010-08-20T20:00:00
Updated: 2016-08-19T15:57:01
Reserved: 2010-06-30T00:00:00
Link: CVE-2010-2531
JSON object: View
NVD Information
Status : Analyzed
Published: 2010-08-20T22:00:01.217
Modified: 2023-01-19T16:39:27.547
Link: CVE-2010-2531
JSON object: View
Redhat Information
No data.
CWE