PHP Hash_Update_File Freed Resource Access Code Execution Vulnerability

PHP is prone to a locally exploitable arbitrary-code-execution vulnerability. This issue stems from a design error.

This issue affects the 'hash_update_file()' function. An attacker can execute arbitrary code by gaining access to freed memory and overwriting it with malicious data.

This issue affects PHP 5.0 through 5.2.1.


 

Privacy Statement
Copyright 2010, SecurityFocus