Description
zend_hash_del_key_or_index in zend_hash.c in PHP before 4.4.3 and 5.x before 5.1.3 can cause zend_hash_del to delete the wrong element, which prevents a variable from being unset even when the PHP unset function is called, which might cause the variable's value to be used in security-relevant operations.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1206-1 | New php4 packages fix several vulnerabilities |
EUVD |
EUVD-2006-3014 | zend_hash_del_key_or_index in zend_hash.c in PHP before 4.4.3 and 5.x before 5.1.3 can cause zend_hash_del to delete the wrong element, which prevents a variable from being unset even when the PHP unset function is called, which might cause the variable's value to be used in security-relevant operations. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T18:16:05.512Z
Reserved: 2006-06-14T00:00:00.000Z
Link: CVE-2006-3017
No data.
Status : Modified
Published: 2006-06-14T23:02:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-3017
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD