Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
AV:N/AC:L/Au:N/C:C/I:C/A:C
Vendors | Products |
---|---|
Microsoft |
|
Php |
|
Configuration 1 [-]
AND |
|
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2012-05-21T15:00:00
Updated: 2017-08-28T12:57:01
Reserved: 2012-04-19T00:00:00
Link: CVE-2012-2376
JSON object: View
NVD Information
Status : Modified
Published: 2012-05-21T15:55:02.117
Modified: 2017-08-29T01:31:35.960
Link: CVE-2012-2376
JSON object: View
Redhat Information
No data.
CWE