Description
A vulnerability has been reported for PHP versions 4.2.0 and 4.2.1.The vulnerability is the result of the PHP interpreter incorrectly parsing MIME headers when HTTP POST commands are received. When PHP receives a malformed POST request, it generates an error condition that is improperly handled. As a result, the attacker may cause the web server to crash and possibly execute supplied code.
Affected PHP versions (4.2.0, 4.2.1).
Remediation
Upgrade PHP to the latest version.
References
Related Vulnerabilities
Perl Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-6329)
MySQL CVE-2013-3812 Vulnerability (CVE-2013-3812)
WordPress Plugin GD bbPress Attachments Cross-Site Scripting (2.5)
MediaWiki CVE-2023-29137 Vulnerability (CVE-2023-29137)
Oracle HTTP Server Out-of-bounds Read Vulnerability (CVE-2018-16890)