CVE-2011-1092 describes an integer overflow vulnerability in the shmop_read function within PHP versions prior to 5.3.6. This flaw allows remote attackers to trigger a denial of service (application crash) and potentially access sensitive memory by providing a large third argument to the affected function. With a CVSS score of 7.5, this vulnerability is considered highly severe due to its network-based attack vector, low attack complexity, and potential for partial confidentiality, integrity, and availability impacts. While not currently on the KEV catalog, public exploit code exists, specifically an ExploitDB entry, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.3.5CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:php:php:1.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:php:php:2.0:*:*:*:*:*:*:* | ||
2.0b10CPE matchmatch criteria | cpe:2.3:a:php:php:2.0b10:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.