PT-2007-3235 · Php · Php

Publicado

2007-04-05

·

Atualizado

2017-07-29

·

CVE-2007-1889

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHP version 5.2.0
Description: The issue is related to an integer signedness error in the zend mm alloc int function within the Zend Memory Manager. This error allows remote attackers to execute arbitrary code by sending a large emalloc request. The problem is due to an incorrect signed long cast. Attacks can be demonstrated via the HTTP SOAP client in PHP or through a call to msg receive with the largest positive integer value of maxsize.
Recommendations: For PHP version 5.2.0, consider updating to a newer version to mitigate the risk, as the current version contains a critical integer signedness error that could lead to arbitrary code execution.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1889
DSA-1283-1
DTSA-39-1

Produtos afetados

Php