Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP Zip扩展_zip_name_locate函数拒绝服务漏洞
Vulnerability Description
PHP(PHP:Hypertext Preprocessor,PHP:超文本预处理器)是PHP Group和开放源代码社区共同维护的一种开源的通用计算机脚本语言。该语言主要用于Web开发,支持多种数据库及操作系统。 PHP 5.3.6之前版本的Zip扩展的zip_name_locate.c中的_zip_name_locate函数没有正确处理ZIPARCHIVE::FL_UNCHANGED参数。上下文攻击者可借助由locateName或statName操作处理的空ZIP存档,导致拒绝服务(空指针解引用)。
CVSS Information
N/A
Vulnerability Type
N/A