Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux

PHP Multiple Denial of Service Vulnerabilities (Windows)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
This host is installed with PHP and is prone to multiple denial of service vulnerabilities.
Insight
Insight
Multiple flaws are due to - An error in application which makes calls to the 'zend_strndup()' function without checking the returned values. A local user can run specially crafted PHP code to trigger a null pointer dereference in zend_strndup() and cause the target service to crash. - An error in 'tidy_diagnose' function, which might allows remote attackers to cause a denial of service via crafted input.
Affected Software
Affected Software
PHP Version 5.3.8 on Windows.
Solution
Solution
Upgrade to PHP version 5.4.0 or later.