PT-2007-2878 · Php · Php
Stefan Esser
·
Publicado
2007-03-16
·
Atualizado
2018-10-19
·
CVE-2007-1484
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHP versions prior to 5.2.1
PHP version 4.4.6 and earlier
Description
The issue is related to the
array user key compare function, which makes erroneous calls to zval dtor, leading to memory corruption. This allows local users to bypass safe mode and execute arbitrary code via a certain unset operation after array user key compare has been called.Recommendations
For PHP versions prior to 5.2.1, update to version 5.2.1 or later to resolve the issue.
For PHP version 4.4.6 and earlier, consider upgrading to a newer version of PHP, as these versions are no longer supported.
As a temporary workaround, consider restricting the use of the
array user key compare function and the zval dtor function until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Php