CVE-2011-1471

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 20 Mar 2011, 01:00
Last modified:06 Aug 2024, 22:28

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
8.04% LOW
8% probability -0.14%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

20 Mar 2011, 01:00
Published
Vulnerability first disclosed
06 Aug 2024, 22:28
Last Modified
Vulnerability information updated

Description

Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 8.04% Percentile: 92%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • UnknownPHP

    < 5.2.11 | ≥ 5.3.0, < 5.3.6

References (10)