PT-2007-2773 · Php · Ovrimos Extension For Php

Published

2007-03-09

·

Updated

2018-10-30

·

CVE-2007-1378

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ovrimos extension for PHP versions prior to 4.4.5
Description The issue is due to the ovrimos longreadlen function in the Ovrimos Extension not properly sanitizing user-supplied input, allowing context-dependent attackers to write to arbitrary memory locations via the result id and length arguments. This may allow an attacker to manipulate arbitrary portions of system memory and execute code, potentially gaining elevated privileges.
Recommendations For Ovrimos extension for PHP versions prior to 4.4.5, update to version 4.4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the ovrimos longreadlen function until a patch is applied. Avoid using the result id and length arguments in the affected function until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1378

Affected Products

Ovrimos Extension For Php