VYPR
Unrated severityNVD Advisory· Published May 7, 2010· Updated Jun 16, 2026

CVE-2010-1861

CVE-2010-1861

Description

The sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to write to arbitrary memory addresses by using an object's __sleep function to interrupt an internal call to the shm_put_var function, which triggers access of a freed resource.

Affected products

17
  • PHP/PHP17 versions
    cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*+ 16 more
    • cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.10:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.11:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.12:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.13:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.2.9:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.3.2:*:*:*:*:*:*:*
    • (no CPE)range: >=5.2,<=5.2.13;>=5.3,<=5.3.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.