Release date:
Updated on:
Affected Systems:
PHP 5.3.x
Unaffected system:
PHP 5.3.6
Description:
--------------------------------------------------------------------------------
Bugtraq id: 46967
Cve id: CVE-2011-1466
PHP is a script language running on a computer. It is mainly used to process dynamic web pages, including command line interfaces or graphical user interface programs.
The implementation of the SdnToJulian function in the Calendar extension of PHP versions earlier than 5.3.6 has the integer overflow vulnerability, which allows attackers to cause denial of service through the first parameter of the cal_from_jd function.
<* Source: m. kocielski
Link: http://bugs.php.net/bug.php? Id = 53574
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.php.net