PT-2006-5282 · Php+1 · Php+1
Publicado
2006-08-31
·
Atualizado
2022-07-19
·
CVE-2006-4482
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PHP versions prior to 5.1.5
Description
Multiple heap-based buffer overflows in the
str repeat and wordwrap functions in ext/standard/string.c have unspecified impact and attack vectors when used on a 64-bit system. These overflows could be exploited by attackers or malicious users to execute arbitrary commands.Recommendations
For PHP versions prior to 5.1.5, update to version 5.1.5 or later to resolve the issue. As a temporary workaround, consider disabling the
str repeat and wordwrap functions until a patch is available. Restrict access to the ext/standard/string.c module to minimize the risk of exploitation. Avoid using the affected functions in sensitive operations until the issue is resolved.Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Php
Red Hat