The iconv_mime_decode_headers function in the Iconv extension in PHP before 5.3.4 does not properly handle encodings that are unrecognized by the iconv and mbstring (aka Multibyte String) implementations, which allows remote attackers to trigger an incomplete output array, and possibly bypass spam detection or have unspecified other impact, via a crafted Subject header in an e-mail message, as demonstrated by the ks_c_5601-1987 character set.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2011-01-18T19:00:00
Updated: 2024-08-07T03:55:34.470Z
Reserved: 2011-01-18T00:00:00
Link: CVE-2010-4699
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-01-18T20:00:10.783
Modified: 2024-11-21T01:21:33.170
Link: CVE-2010-4699
Redhat