← Back

CVE-2013-3735

nvd nist
Published: May 31, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The Zend Engine in PHP before 5.4.16 RC1, and 5.5.0 before RC2, does not properly determine whether a parser error occurred, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted function definition, as demonstrated by an attack within a shared web-hosting environment. NOTE: the vendor's http://php.net/security-note.php page says "for critical security situations you should be using OS-level security by running multiple web servers each as their own user id.

Affected (31)

Products: Php: Php
1 product
Php
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Php
Up to 5.4.15
Version 5.4.0
Version 5.4.10
Version 5.4.11
Version 5.4.12
Version 5.4.12 rc1
Version 5.4.12 rc2
Version 5.4.13
Version 5.4.13 rc1
Version 5.4.14
Version 5.4.14 rc1
Version 5.4.1
Version 5.4.2
Version 5.4.3
Version 5.4.4
Version 5.4.5
Version 5.4.6
Version 5.4.7
Version 5.4.8
Version 5.4.9
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
Php
Up to 5.5.0
Version 5.5.0 alpha1
Version 5.5.0 alpha2
Version 5.5.0 alpha3
Version 5.5.0 alpha4
Version 5.5.0 alpha5
Version 5.5.0 alpha6
Version 5.5.0 beta1
Version 5.5.0 beta2
Version 5.5.0 beta3
Version 5.5.0 beta4

References (8)

Timeline

No history available yet.