PT-2007-2805 · Microsoft+1 · Ntwdblib.Dll+1

Rgod

·

Published

2007-03-10

·

Updated

2018-10-19

·

CVE-2007-1411

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 4.4.7 PHP 5 versions (affected versions not specified)
Description The issue is caused by a buffer overflow that allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the mssql connect and mssql pconnect functions. This is due to a boundary error when processing arguments within the dbopen() function in NTWDBLIB.DLL. The vulnerability can be exploited by passing an overly long string (greater than 260 bytes) as an argument to the mssql connect() or mssql pconnect() functions, allowing attackers to bypass security restrictions like the disable functions directive.
Recommendations For PHP versions prior to 4.4.7, consider upgrading to a newer version to mitigate the risk. For PHP 5 versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the mssql connect() and mssql pconnect() functions until a patch is available.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1411

Affected Products

Ntwdblib.Dll
Php