CVE-2006-1490 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 21% (pctl 97)
Patch early
A public exploit exists.
Description
PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 20.97% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-03-29 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| php | php |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PHP 4.x/5.x - 'Html_Entity_Decode()' Information Disclosure | 2006-03-29 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc
- http://bugs.gentoo.org/show_bug.cgi?id=127939
- http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/html.c?r1=1.112&r2=1.113
- http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/html.c?view=log
- http://docs.info.apple.com/article.html?artnum=304829
- http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html
- http://rhn.redhat.com/errata/RHSA-2006-0276.html
- http://secunia.com/advisories/19383
- http://secunia.com/advisories/19499
- http://secunia.com/advisories/19570
- http://secunia.com/advisories/19832
- http://secunia.com/advisories/19979
- http://secunia.com/advisories/20052
- http://secunia.com/advisories/20210
- http://secunia.com/advisories/20951
- http://secunia.com/advisories/21125
- http://secunia.com/advisories/23155
- http://security.gentoo.org/glsa/glsa-200605-08.xml
- http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:063
→ the Explorer · watch your stack · NVD