CVE-2010-1860
Publication date 7 May 2010
Last updated 24 July 2024
Ubuntu priority
Description
The html_entity_decode function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal call, related to the call time pass by reference feature.
Notes
mdeslaur
This is MOPS-2010-010 reproducer in report interruption issue, safe_mode - open_basedir bypass, ignoring See CVE-2010-1864 for patch