PT-2007-2847 · Php Development Team · Php

Publicado

2007-03-14

·

Atualizado

2008-09-05

·

CVE-2007-1453

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP version 5.2.0
Description A buffer underflow issue exists in the filtering extension of PHP, specifically in the PHP FILTER TRIM DEFAULT macro. This allows attackers to execute arbitrary code by calling the filter var function with certain modes, such as FILTER VALIDATE INT. The issue arises when filter writes a null byte in whitespace preceding the buffer.
Recommendations For PHP version 5.2.0, consider disabling the filter var function with modes like FILTER VALIDATE INT until a patch is available to prevent potential code execution. Restrict access to the filtering extension to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1453
DSA-1283-1
DTSA-39-1

Produtos afetados

Php