PT-2003-1921 · Php+1 · Php+1

Stefan Esser

·

Published

2003-10-15

·

Updated

2018-10-30

·

CVE-2003-0861

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 4.3.3
Description The issue concerns integer overflows in two components: (1) the base64 encode function and (2) the GD library. These overflows may result in the corruption of sensitive regions of memory. The estimated number of potentially affected devices worldwide and details about real-world incidents where this issue was exploited are not specified.
Recommendations For PHP versions prior to 4.3.3, update to version 4.3.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the base64 encode function and the GD library until a patch is available. Avoid using these components in sensitive operations to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0861

Affected Products

Gd Library
Php