Release date:
Updated on:
Affected Systems:
PHP 5.4.x
Unaffected system:
PHP 5.4.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53455
Cve id: CVE-2012-2329
PHP is an embedded HTML language. PHP is similar to Microsoft's ASP. It is a script language that is executed on the server side and embedded in HTML documents, the language style is similar to the C language and is widely used by many website programmers.
PHP has a buffer overflow vulnerability. Attackers can exploit this vulnerability to execute arbitrary machine code in the PHP process.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.php.net