Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 4092506
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 20, 20262026-05-20T19:30:00+00:00 2026-05-20T19:30:00+00:00

I currently have a web server running PHP 5.2.13 and have recently been told:

  • 0

I currently have a web server running PHP 5.2.13 and have recently been told:

Synopsis :

The remote web server uses a version of PHP that is affected by
multiple flaws.

Description :

According to its banner, the version of PHP 5.2 installed on the
remote host is older than 5.2.15. Such versions may be affected by
several security issues :

  • A crash in the zip extract method.

  • A possible double free exists in the imap extension.
    (CVE-2010-4150)

  • An unspecified flaw exists in ‘open_basedir’.
    (CVE-2010-3436)

  • A possible crash could occur in ‘mssql_fetch_batch()’.

  • A NULL pointer dereference exists in
    ‘ZipArchive::getArchiveComment’. (CVE-2010-3709)

  • A crash exists if anti-aliasing steps are invalid.
    (Bug #53492)

  • A crash exists in pdo_firebird getAttribute(). (Bug 53323)

  • A user-after-free vulnerability in the Zend engine when
    a ‘_set()’, ‘_get()’, ‘_isset()’ or ‘_unset()’
    method is called can allow for a denial of service
    attack. (Bug #52879 / CVE-2010-4697)

  • A stack-based buffer overflow exists in the
    ‘imagepstext()’ function in the GD extension. (Bug 53492 / CVE-2010-4698)

  • An error exists when processing invalid XML-RPC
    requests that can lead to a NULL pointer
    dereference. (bug #51288) (CVE-2010-0397)

  • An error exists in the function ‘fnmatch’ that can lead
    to stack exhaustion.

  • An error exists in the sqlite extension that could
    allow arbitrary memory access.

  • A memory corruption error exists in the function
    ‘substr_replace’.

  • The following functions are not properly protected
    against function interruptions :

addcslashes, chunk_split, html_entity_decode,
iconv_mime_decode, iconv_substr, iconv_mime_encode,
htmlentities, htmlspecialchars, str_getcsv,
http_build_query, strpbrk, strstr, str_pad,
str_word_count, wordwrap, strtok, setcookie,
strip_tags, trim, ltrim, rtrim, parse_str, pack, unpack,
uasort, preg_match, strrchr, strchr, substr, str_repeat
(CVE-2010-1860, CVE-2010-1862, CVE-2010-1864,
CVE-2010-2097, CVE-2010-2100, CVE-2010-2101,
CVE-2010-2190, CVE-2010-2191, CVE-2010-2484)

  • The following opcodes are not properly protected
    against function interruptions :

ZEND_CONCAT, ZEND_ASSIGN_CONCAT, ZEND_FETCH_RW
(CVE-2010-2191)

  • The default session serializer contains an error
    that can be exploited when assigning session
    variables having user defined names. Arbitrary
    serialized values can be injected into sessions by
    including the PS_UNDEF_MARKER, ‘!’, character in
    variable names.

  • A use-after-free error exists in the function
    ‘spl_object_storage_attach’. (CVE-2010-2225)


I’m not using a lot of these e.g. mssql_fetch_batch(), pdo_firebird getAttribute…

Basically I curious to know if this is all a major concern?

Thanks,

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-20T19:30:00+00:00Added an answer on May 20, 2026 at 7:30 pm

    When software updates are released (especially server software and code interpreters), there is always a good reason.

    Do yourself a favor and update regularly your software packages. If security advisories have been released, don’t wait up and update right away.

    There are not a lot of changes to take into consideration between the PHP 5.2 branch and the 5.3 branch. One day, support for the 5.2 branch will be dropped and you’ll be forced to upgrade anyway. Take a look at the PHP 5.3.x Migration Guide.


    • The following opcodes are not properly protected against function interruptions :
      ZEND_CONCAT, ZEND_ASSIGN_CONCAT, ZEND_FETCH_RW (CVE-2010-2191)

    Don’t tell me you don’t use string concatenation (.) and assignment concatenation (.=) in your code.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I currently have an asp.net website hosted on two web servers that sit behind
I have a web application that currently sends emails. At the time my web
Currently I have an application that receives an uploaded file from my web application.
I have a web application that's branded according to the user that's currently logged
Let's say I have a web page that currently accepts a single ID value
I have an internal enterprise app that currently consumes 10 different web services. They're
A very flowery title indeed. I have a PHP web application that is in
Currently I have a section of code that needs to make about 7 web
I'm dealing with a LAMP web server. I have forms that users use to
I have a PHP web application running on IIS, which allows a user to

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.