SB2013071603 - Buffer overflow in php (Alpine package)
Published: July 16, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2013-4113)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=1a8b152e8a88f0dbf4b4041048286b6c17476061
- https://git.alpinelinux.org/aports/commit/?id=557e3af1ace8b185c2831c4ebe37fc8c5326c189
- https://git.alpinelinux.org/aports/commit/?id=1be6dba9064c72276b4cebc2a9ade9b279d90d84
- https://git.alpinelinux.org/aports/commit/?id=805bb44105b1f929aabd924795f9b6280fc50f82