CVE-2009-4418

Publication date 24 December 2009

Last updated 24 July 2024


Ubuntu priority

Description

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 9.10 karmic Ignored
9.04 jaunty Ignored
8.10 intrepid Ignored
8.04 LTS hardy Ignored
6.06 LTS dapper Ignored

Notes


mdeslaur

as of 2010/01/04, not fixed yet can only be exploited by a malicious script, not a security issue. Marking as ignored.