CVE-2012-2335
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2012-2335 from the MITRE CVE dictionary dictionary and NIST NVD.
Statement
The mitigation for CVE-2012-2335 is included in the following PHP updates for Red Hat Enterprise Linux 5 and 6, which also address CVE-2012-2336 (BZ#820708):
https://rhn.redhat.com/errata/RHSA-2012-1045.html
https://rhn.redhat.com/errata/RHSA-2012-1046.html
https://rhn.redhat.com/errata/RHSA-2012-1047.html
CVSS v2 metrics
NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.
| Base Score | 5.1 |
|---|---|
| Base Metrics | AV:N/AC:H/Au:N/C:P/I:P/A:P |
| Access Vector | Network |
| Access Complexity | High |
| Authentication | None |
| Confidentiality Impact | Partial |
| Integrity Impact | Partial |
| Availability Impact | Partial |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Affected Packages State
| Platform | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | php | Will not fix |
| Red Hat Enterprise Linux 5 | php53 | Will not fix |
| Red Hat Enterprise Linux 5 | php | Will not fix |
| Red Hat Enterprise Linux 4 | php | Not affected |
| Red Hat Enterprise Linux 3 | php | Not affected |
| Red Hat Application Stack v2 for Enterprise Linux (v.5) | php | Will not fix |
CVE description copyright © 2017, The MITRE Corporation
