CVE-2010-4156
Publication date 9 November 2010
Last updated 24 July 2024
Ubuntu priority
The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).
Status
Package | Ubuntu Release | Status |
---|---|---|
php5 | ||
Notes
sbeattie
does not affect lucid, as the version of libmbfl in that version is 1.0.2; see ext/mbstring/libmbfl/configure.in
Patch details
Package | Patch details |
---|---|
php5 |
References
Related Ubuntu Security Notices (USN)
- USN-1042-1
- PHP vulnerabilities
- 11 January 2011