PT-2007-3078 · Php+1 · Php+1

Publicado

2007-03-27

·

Atualizado

2018-10-16

·

CVE-2007-1711

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHP versions 4.4.5 through 4.4.6
Description: A double free vulnerability exists in the unserializer, allowing context-dependent attackers to execute arbitrary code. This can be achieved by overwriting variables pointing to the GLOBALS array or the session data in SESSION.
Recommendations: For PHP versions 4.4.5 through 4.4.6, consider disabling the unserializer function until a patch is available. Restrict access to session data to minimize the risk of exploitation. Avoid using the GLOBALS array in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1711
DSA-1282-1
DSA-1283-1
RHSA-2007:0154
RHSA-2007:0155
RHSA-2007:0163
RHSA-2007_0155

Produtos afetados

Php
Red Hat