PT-2007-2847 · Php Development Team · Php

Published

2007-03-14

·

Updated

2008-09-05

·

CVE-2007-1453

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP version 5.2.0
Description A buffer underflow issue exists in the filtering extension of PHP, specifically in the PHP FILTER TRIM DEFAULT macro. This allows attackers to execute arbitrary code by calling the filter var function with certain modes, such as FILTER VALIDATE INT. The issue arises when filter writes a null byte in whitespace preceding the buffer.
Recommendations For PHP version 5.2.0, consider disabling the filter var function with modes like FILTER VALIDATE INT until a patch is available to prevent potential code execution. Restrict access to the filtering extension to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1453
DSA-1283-1
DTSA-39-1

Affected Products

Php