CVE-2010-4657
Publication date 13 November 2019
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| php5 | 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty |
Not affected
|
|
Notes
jdstrand
per Debian, This was initially reported to be a bug in libxml2, but it later showed that PHP
mdeslaur
can't reproduce on quantal+ The reproducer only displays garbage if the suhosin patch is applied, which is why it doesn't appear to work on quantal+ Need to check if libxml2 still walks past the end of the string if the suhosin patch isn't applied. we will not be fixing this issue
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.5 · High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N