CVE-2006-3017
Last modified
CVE-2006-3017 is a vulnerability of currently unknown severity. zend_hash_del_key_or_index in zend_hash.c in PHP before 4.4.3 and 5.x before 5.1.3 can cause zend_hash_del to delete the wrong element, which prevents a variable from being unset even when the PHP unset function is called, which might cause the variable's value to be used in security-relevant operations.. EPSS estimates a 4.06% chance of exploitation in the next 30 days.
Description
zend_hash_del_key_or_index in zend_hash.c in PHP before 4.4.3 and 5.x before 5.1.3 can cause zend_hash_del to delete the wrong element, which prevents a variable from being unset even when the PHP unset function is called, which might cause the variable's value to be used in security-relevant operations.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Php | Php | <= 4.4.2 | — |
| Php | Php | 3.0 | — |
| Php | Php | 3.0.1 | — |
| Php | Php | 3.0.2 | — |
| Php | Php | 3.0.3 | — |
| Php | Php | 3.0.4 | — |
| Php | Php | 3.0.5 | — |
| Php | Php | 3.0.6 | — |
| Php | Php | 3.0.7 | — |
| Php | Php | 3.0.8 | — |
| Php | Php | 3.0.9 | — |
| Php | Php | 3.0.10 | — |
| Php | Php | 3.0.11 | — |
| Php | Php | 3.0.12 | — |
| Php | Php | 3.0.13 | — |
| Php | Php | 3.0.14 | — |
| Php | Php | 3.0.15 | — |
| Php | Php | 3.0.16 | — |
| Php | Php | 3.0.17 | — |
| Php | Php | 3.0.18 | — |
| Php | Php | 4.0 | — |
| Php | Php | 4.0.0 | — |
| Php | Php | 4.0.1 | — |
| Php | Php | 4.0.2 | — |
| Php | Php | 4.0.3 | — |
| Php | Php | 4.0.4 | — |
| Php | Php | 4.0.5 | — |
| Php | Php | 4.0.6 | — |
| Php | Php | 4.0.7 | — |
| Php | Php | 4.1.0 | — |
| Php | Php | 4.1.1 | — |
| Php | Php | 4.1.2 | — |
| Php | Php | 4.2 | — |
| Php | Php | 4.2.0 | — |
| Php | Php | 4.2.1 | — |
| Php | Php | 4.2.2 | — |
| Php | Php | 4.2.3 | — |
| Php | Php | 4.3.0 | — |
| Php | Php | 4.3.1 | — |
| Php | Php | 4.3.2 | — |
| Php | Php | 4.3.3 | — |
| Php | Php | 4.3.4 | — |
| Php | Php | 4.3.5 | — |
| Php | Php | 4.3.6 | — |
| Php | Php | 4.3.7 | — |
| Php | Php | 4.3.8 | — |
| Php | Php | 4.3.9 | — |
| Php | Php | 4.3.10 | — |
| Php | Php | 4.3.11 | — |
| Php | Php | 4.4.0 | — |
Showing 50 of 62 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/19927Vendor Advisory
- http://secunia.com/advisories/21031Vendor Advisory
- http://secunia.com/advisories/21050Vendor Advisory
- http://secunia.com/advisories/21125Vendor Advisory
- http://secunia.com/advisories/21135Vendor Advisory
- http://secunia.com/advisories/21202Vendor Advisory
- http://secunia.com/advisories/21252Vendor Advisory
- http://secunia.com/advisories/21723Vendor Advisory
- http://secunia.com/advisories/22225Vendor Advisory
- http://secunia.com/advisories/22713Vendor Advisory
- http://secunia.com/advisories/19927Vendor Advisory
- http://secunia.com/advisories/21031Vendor Advisory
- http://secunia.com/advisories/21050Vendor Advisory
- http://secunia.com/advisories/21125Vendor Advisory
- http://secunia.com/advisories/21135Vendor Advisory
- http://secunia.com/advisories/21202Vendor Advisory
- http://secunia.com/advisories/21252Vendor Advisory
- http://secunia.com/advisories/21723Vendor Advisory
- http://secunia.com/advisories/22225Vendor Advisory
- http://secunia.com/advisories/22713Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-3017?
How severe is CVE-2006-3017?
How do I fix CVE-2006-3017?
Are you affected by CVE-2006-3017?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
