~tsimonq2/ubuntu-cve-tracker/triage

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
Candidate: CVE-2010-1861
PublicDate: 2010-05-07
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1861
 http://php-security.org/2010/05/05/mops-2010-009-php-shm_put_var-already-freed-resource-access-vulnerability/index.html
 http://www.php.net/releases/5_3_3.php
Description:
 The sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2
 allows context-dependent attackers to write to arbitrary memory addresses
 by using an object's __sleep function to interrupt an internal call to the
 shm_put_var function, which triggers access of a freed resource.
Ubuntu-Description:
Notes:
 mdeslaur> This is MOPS-2010-009
 mdeslaur> interruption issue, safe_mode - open_basedir bypass, ignoring
Bugs:
Priority: low
Discovered-by: Stefan Esser
Assigned-to:

Patches_php5:
 upstream: http://svn.php.net/viewvc?view=revision&revision=299328 (5.3) (no patch for 5.2?)
upstream_php5: released (5.3.3)
dapper_php5: ignored
hardy_php5: ignored
jaunty_php5: ignored
karmic_php5: ignored
lucid_php5: ignored
devel_php5: not-affected (5.3.3-1ubuntu6)