CVE

Id
49383  
CVE No.
CVE-2011-1471  
Status
Candidate  
Description
Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls.  
Phase
Assigned (20110319)  
Votes
None (candidate not yet proposed)  
Comments