Release date:
Updated on:
Affected Systems:
PHP 5.3.8
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51992
Cve id: CVE-2012-0781
PHP is a script language running on a computer. It is mainly used to process dynamic web pages, including command line interfaces or graphical user interface programs.
When processing specially crafted input, the tidy_diagnose function in PHP 5.3.8 allows remote attackers to perform the Tidy: diagnose operation on invalid objects, resulting in DOS.
<* Source: Maksymilian Arciemowicz (max@jestsuper.pl)
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 782951
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.php.net