CVE-2012-2376

Publication date 21 May 2012

Last updated 24 July 2024


Ubuntu priority

Description

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 12.04 LTS precise Ignored
11.10 oneiric Ignored
11.04 natty Ignored
10.04 LTS lucid Ignored
8.04 LTS hardy Ignored

Notes


jdstrand

Windows-only