Description
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991.
Remediation
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-3848)
Jboss EAP Cryptographic Issues Vulnerability (CVE-2014-0035)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4288)
WordPress Plugin Import XML and RSS Feeds Arbitrary File Upload (2.1.3)