Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:PHP:XML-HEAP-MEM-CORR

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

PHP xml_parse_into_struct Heap Memory Corruption

Release Date

2013/08/07

Update Number

2288

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: PHP xml_parse_into_struct Heap Memory Corruption


This signature detects attempts to exploit a known vulnerability against xml_parse_into_struct() function in PHP. A successful attack can lead to arbitrary code execution.

Extended Description

ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.

Affected Products

  • php 5.3.0
  • php 5.3.1
  • php 5.3.10
  • php 5.3.11
  • php 5.3.12
  • php 5.3.13
  • php 5.3.14
  • php 5.3.15
  • php 5.3.16
  • php 5.3.17
  • php 5.3.18
  • php 5.3.19
  • php 5.3.2
  • php 5.3.20
  • php 5.3.21
  • php 5.3.22
  • php 5.3.23
  • php 5.3.24
  • php 5.3.25
  • php 5.3.3
  • php 5.3.4
  • php 5.3.5
  • php 5.3.6
  • php 5.3.7
  • php 5.3.8
  • php 5.3.9
  • php up to 5.3.26

References

  • BugTraq: 61128
  • CVE: CVE-2013-4113

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out