"value":"Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback."
},
{
"lang":"es",
"value":"Desbordamiento de b\u00fafer basado en pila en el envoltorio (wrapper) de URL zip:// en PECL ZIP 1.8.3 y anteriores, como ha sido incluido en PHP 5.2.0 y 5.2.1, permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n mediante una URL zip:// larga, como ha sido demostrado accediendo activamente a la URL desde un int\u00e9rprete PHP remoto mediante una subida avatar o notificaci\u00f3n de que el blog ha sido enlazado (blog pingback)."
}
],
"vendorComments":[
{
"organization":"Red Hat",
"comment":"Not vulnerable. The zip extension was not shipped in versions of PHP \nprovided for Red Hat Enterprise Linux 2.1, 3, 4, 5, Stronghold 4.0, or\nRed Hat Application Stack 1.",