PT-2006-5282 · Php+1 · Php+1

Publicado

2006-08-31

·

Atualizado

2022-07-19

·

CVE-2006-4482

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.1.5
Description Multiple heap-based buffer overflows in the str repeat and wordwrap functions in ext/standard/string.c have unspecified impact and attack vectors when used on a 64-bit system. These overflows could be exploited by attackers or malicious users to execute arbitrary commands.
Recommendations For PHP versions prior to 5.1.5, update to version 5.1.5 or later to resolve the issue. As a temporary workaround, consider disabling the str repeat and wordwrap functions until a patch is available. Restrict access to the ext/standard/string.c module to minimize the risk of exploitation. Avoid using the affected functions in sensitive operations until the issue is resolved.

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-4482
DSA-1206-1
RHSA-2006:0669
RHSA-2006:0688
RHSA-2006_0669

Produtos afetados

Php
Red Hat