CVE-2011-3379

Publication date 3 November 2011

Last updated 24 July 2024


Ubuntu priority

Description

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy
Not affected

Notes


mdeslaur

looks like it's 5.3.7 and 5.3.8