PT-2007-3078 · Php+1 · Php+1

Published

2007-03-27

·

Updated

2018-10-16

·

CVE-2007-1711

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHP versions 4.4.5 through 4.4.6
Description: A double free vulnerability exists in the unserializer, allowing context-dependent attackers to execute arbitrary code. This can be achieved by overwriting variables pointing to the GLOBALS array or the session data in SESSION.
Recommendations: For PHP versions 4.4.5 through 4.4.6, consider disabling the unserializer function until a patch is available. Restrict access to session data to minimize the risk of exploitation. Avoid using the GLOBALS array in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1711
DSA-1282-1
DSA-1283-1
RHSA-2007:0154
RHSA-2007:0155
RHSA-2007:0163
RHSA-2007_0155

Affected Products

Php
Red Hat