Description
mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function; or (2) trigger a heap-based buffer overflow via a modified length value, which is not properly handled by the php_mysqlnd_rset_header_read function.
Remediation
References
Related Vulnerabilities
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-15700)
WordPress Plugin Social Review includes Backdoor [Only if downloaded via the vendor website] (1.0.8)
Apache Tomcat Other Vulnerability (CVE-2003-0043)
Payara URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-7312)
WordPress Plugin Auto Prune Posts Cross-Site Request Forgery (1.8.0)