PT-2007-2773 · Php · Ovrimos Extension For Php
Published
2007-03-09
·
Updated
2018-10-30
·
CVE-2007-1378
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ovrimos extension for PHP versions prior to 4.4.5
Description
The issue is due to the ovrimos longreadlen function in the Ovrimos Extension not properly sanitizing user-supplied input, allowing context-dependent attackers to write to arbitrary memory locations via the
result id and length arguments. This may allow an attacker to manipulate arbitrary portions of system memory and execute code, potentially gaining elevated privileges.Recommendations
For Ovrimos extension for PHP versions prior to 4.4.5, update to version 4.4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the ovrimos longreadlen function until a patch is applied. Avoid using the
result id and length arguments in the affected function until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ovrimos Extension For Php