PT-2008-4268 · Php+1 · Php+1

Publicado

2008-06-23

·

Atualizado

2019-10-09

·

CVE-2008-2829

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions PHP versions 4.x through 5.2.6
Description The issue allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request. This request triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822 write address function.
Recommendations For PHP versions 4.x through 5.2.6, consider updating to a version that does not use obsolete API calls to mitigate the risk of a denial of service or arbitrary code execution. As a temporary workaround, consider restricting the length of IMAP requests to prevent the buffer overflow error.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2829
DTSA-144-1
HPSBUX02431
HPSBUX02465

Produtos afetados

Hp-Ux
Php