Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions.

Project Subscriptions

Vendors Products
Enterprise Linux Subscribe
Rhel Application Stack Subscribe
Rhel Stronghold Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1206-1 New php4 packages fix several vulnerabilities
Ubuntu USN Ubuntu USN USN-375-1 PHP vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
ftp://patches.sgi.com/support/free/security/advisories/20061101-01-P cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=304829 cve-icon cve-icon
http://issues.rpath.com/browse/RPL-761 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2006-0736.html cve-icon cve-icon
http://secunia.com/advisories/22653 cve-icon cve-icon
http://secunia.com/advisories/22685 cve-icon cve-icon
http://secunia.com/advisories/22688 cve-icon cve-icon
http://secunia.com/advisories/22693 cve-icon cve-icon
http://secunia.com/advisories/22713 cve-icon cve-icon
http://secunia.com/advisories/22753 cve-icon cve-icon
http://secunia.com/advisories/22759 cve-icon cve-icon
http://secunia.com/advisories/22779 cve-icon cve-icon
http://secunia.com/advisories/22881 cve-icon cve-icon
http://secunia.com/advisories/22929 cve-icon cve-icon
http://secunia.com/advisories/23139 cve-icon cve-icon
http://secunia.com/advisories/23155 cve-icon cve-icon
http://secunia.com/advisories/23247 cve-icon cve-icon
http://secunia.com/advisories/24606 cve-icon cve-icon
http://secunia.com/advisories/25047 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200703-21.xml cve-icon cve-icon
http://securitytracker.com/id?1017152 cve-icon cve-icon
http://securitytracker.com/id?1017296 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2006-245.htm cve-icon cve-icon
http://www.cisco.com/en/US/products/products_security_response09186a008082c4fe.html cve-icon cve-icon
http://www.cisco.com/warp/public/707/cisco-air-20070425-http.shtml cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1206 cve-icon cve-icon
http://www.hardened-php.net/advisory_132006.138.html cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:196 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2006_67_php.html cve-icon cve-icon
http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.028.html cve-icon cve-icon
http://www.php.net/releases/5_2_0.php cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0730.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0731.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/450431/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/451098/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/453024/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/20879 cve-icon cve-icon
http://www.trustix.org/errata/2006/0061/ cve-icon cve-icon
http://www.turbolinux.com/security/2006/TLSA-2006-38.txt cve-icon cve-icon
http://www.ubuntu.com/usn/usn-375-1 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA06-333A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4317 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4749 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4750 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1546 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/29971 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2006-5465 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10240 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2006-5465 cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T19:48:30.543Z

Reserved: 2006-10-23T00:00:00

Link: CVE-2006-5465

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-11-04T00:07:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2006-5465

cve-icon Redhat

Severity : Important

Publid Date: 2006-11-02T00:00:00Z

Links: CVE-2006-5465 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses