Hide Forgot
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-0831 to the following vulnerability: Name: CVE-2012-0831 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0831 Assigned: 20120119 Reference: http://svn.php.net/viewvc?view=revision&revision=323016 Reference: https://launchpadlibrarian.net/92454212/php5_5.3.2-1ubuntu4.13.diff.gz Reference: UBUNTU:USN-1358-1 Reference: http://www.ubuntu.com/usn/USN-1358-1 Reference: http://www.securityfocus.com/bid/51954 PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.
There was a regression in the fix, which was released with php-5.3.10, more details at: https://bugs.php.net/bug.php?id=61043
Created php tracking bugs for this issue Affects: fedora-all [bug 790676]
PHP 5.3.11 fixed the regression noted in comment #2: * Fixed bug #61043 (Regression in magic_quotes_gpc fix for CVE-2012-0831). as per: http://www.php.net/archive/2012.php#id2012-04-26-1
php-5.3.11-1.fc15, php-eaccelerator-0.9.6.1-9.fc15.3, maniadrive-1.2-32.fc15.3 has been pushed to the Fedora 15 stable repository. If problems still persist, please make note of it in this bug report.
php-5.3.11-1.fc16, php-eaccelerator-0.9.6.1-9.fc16.3, maniadrive-1.2-32.fc16.3 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:0514 https://rhn.redhat.com/errata/RHSA-2013-0514.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:1307 https://rhn.redhat.com/errata/RHSA-2013-1307.html
Statement: This issue does not affect the version of php as shipped with Red Hat Enterprise Linux 5.