CVE-2010-3709 describes a denial-of-service vulnerability affecting PHP versions 5.2.x through 5.2.14 and 5.3.x through 5.3.3, specifically within the ZipArchive::getArchiveComment function. An attacker can trigger a NULL pointer dereference and application crash by providing a specially crafted ZIP archive. The vulnerability has a CVSS score of 4.3, indicating a medium severity, and requires medium attack complexity with no authentication, leading to a partial availability impact. While not on the KEV catalog and with no active Metasploit or Nuclei exploits, a public exploit (EDB-15431) exists, though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.2.0, < 5.2.15CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 5.3.0, < 5.3.4CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:* | ||
8.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:* | ||
9.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.