VYPR
Unrated severityNVD Advisory· Published Aug 20, 2010· Updated Jun 16, 2026

CVE-2010-3064

CVE-2010-3064

Description

Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function.

Affected products

4
  • PHP/PHP4 versions
    cpe:2.3:a:php:php:5.3.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:php:php:5.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:5.3.2:*:*:*:*:*:*:*
    • (no CPE)range: >=5.3, <=5.3.2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.