FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-11-23 16:00:18 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
2a41233d-10e7-11e0-becc-0022156e8794php-zip -- multiple Denial of Service vulnerabilities

The following DoS conditions in Zip extension were fixed in PHP 5.3.4 and PHP 5.2.15:

  • Fixed crash in zip extract method (possible CWE-170).

  • The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.


Discovery 2010-12-13
Entry 2011-01-13
php5-zip
< 5.3.4

php52-zip
< 5.2.15

CVE-2010-3709
http://www.php.net/releases/5_3_4.php
http://www.php.net/releases/5_2_15.php
http://securityreason.com/achievement_securityalert/90
fe853666-56ce-11e0-9668-001fd0d616cfphp -- ZipArchive segfault with FL_UNCHANGED on empty archive

US-CERT/NIST reports:

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (application crash) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.


Discovery 2011-03-20
Entry 2011-03-25
php5-zip
< 5.3.6

CVE-2011-0421