Common Vulnerabilities and Exposures assigned an identifier CVE-2009-5016 to the following vulnerability: Name: CVE-2009-5016 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5016 Assigned: 20101112 Reference: MISC: http://sirdarckcat.blogspot.com/2009/10/couple-of-unicode-issues-on-php-and.html Reference: MISC: http://www.blackhat.com/presentations/bh-usa-09/VELANAVA/BHUSA09-VelaNava-FavoriteXSS-SLIDES.pdf Reference: CONFIRM: http://bugs.php.net/bug.php?id=49687 Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.
CVE duplicate? http://bugs.php.net/bug.php?id=49687 [2010-11-02 15:34 UTC] pajoye CVE-2010-3870 has been assigned to this issue.
Oops nevermind. xml_utf8_decode != utf8_decode
How is this different from: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3870 ?
Ignore my last statement, however it seems that the svn fix for 2010-3870 fixed this issue as well: http://svn.php.net/viewvc/?view=revision&revision=304959
Created php tracking bugs for this issue Affects: fedora-all [bug 649186]
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5 Via RHSA-2010:0919 https://rhn.redhat.com/errata/RHSA-2010-0919.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2011:0195 https://rhn.redhat.com/errata/RHSA-2011-0195.html