Search

published date: July 27, 2004

CVE-2004-0594 : The memory_limit functionality in...

Description

The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization of key data structures is complete.

Product(s):

  • OpenPKG 2.0
  • OpenPKG 2.1
  • PHP
  • PHP PHP 4.0.0
  • PHP PHP 4.0.1
  • PHP 4.0.1 -

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-0594, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-0594 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?