PT-2007-2806 · Clibpdf+1 · Clibpdf+1

Rgod

·

Publicado

2007-03-12

·

Atualizado

2017-10-11

·

CVE-2007-1412

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP version 4.4.6
Description The issue allows context-dependent attackers to obtain sensitive information, specifically script source code, by providing a long string in the second argument to the cpdf open function in the ClibPDF (cpdf) extension.
Recommendations For PHP version 4.4.6, consider restricting the use of the cpdf open function until a patch is available, or apply configuration changes to limit the input length for the second argument to prevent exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1412

Produtos afetados

Clibpdf
Php