CVE-2010-4156

The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:php:php:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.2:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.3:*:*:*:*:*:*:*
cpe:2.3:a:scottmac:libmbfl:1.1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-11-10 03:00

Updated : 2024-02-04 17:54


NVD link : CVE-2010-4156

Mitre link : CVE-2010-4156

CVE.ORG link : CVE-2010-4156


JSON object : View

Products Affected

scottmac

  • libmbfl

php

  • php
CWE
CWE-20

Improper Input Validation