Description
The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources. NOTE: it was later reported that PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 are also affected.
Remediation
References
Related Vulnerabilities
WordPress Plugin Student Result or Employee Database Security Bypass (1.6.3)
Apache HTTP Server Out-of-bounds Write Vulnerability (CVE-2006-20001)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-12167)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6112)