CVE-2009-2626
Publication date 1 December 2009
Last updated 24 July 2024
Ubuntu priority
The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable.
Status
Package | Ubuntu Release | Status |
---|---|---|
php5 | 9.10 karmic |
Fixed 5.2.10.dfsg.1-2ubuntu6.4
|
9.04 jaunty |
Fixed 5.2.6.dfsg.1-3ubuntu4.5
|
|
8.10 intrepid |
Fixed 5.2.6-2ubuntu4.6
|
|
8.04 LTS hardy |
Fixed 5.2.4-2ubuntu5.10
|
|
6.06 LTS dapper |
Fixed 5.1.2-1ubuntu3.18
|
Patch details
Package | Patch details |
---|---|
php5 |
References
Related Ubuntu Security Notices (USN)
- USN-882-1
- PHP vulnerabilities
- 13 January 2010