PT-2007-3235 · Php · Php
Publicado
2007-04-05
·
Atualizado
2017-07-29
·
CVE-2007-1889
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PHP version 5.2.0
Description:
The issue is related to an integer signedness error in the zend mm alloc int function within the Zend Memory Manager. This error allows remote attackers to execute arbitrary code by sending a large emalloc request. The problem is due to an incorrect signed long cast. Attacks can be demonstrated via the HTTP SOAP client in PHP or through a call to
msg receive with the largest positive integer value of maxsize.Recommendations:
For PHP version 5.2.0, consider updating to a newer version to mitigate the risk, as the current version contains a critical integer signedness error that could lead to arbitrary code execution.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Php