Description
The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the application to exceed limits for memory, execution time, or recursion.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2262-2 | php5 update |
Debian DSA |
DSA-2266-1 | php5 security update |
EUVD |
EUVD-2010-2535 | The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the application to exceed limits for memory, execution time, or recursion. |
Ubuntu USN |
USN-989-1 | PHP vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T02:39:37.384Z
Reserved: 2010-06-30T00:00:00.000Z
Link: CVE-2010-2531
No data.
Status : Deferred
Published: 2010-08-20T22:00:01.217
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-2531
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN