PT-2007-4148 · Php · Php

Published

2007-05-24

·

Updated

2018-10-30

·

CVE-2007-2844

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions 4.x through 5.2.0
Description The issue arises from the lack of thread safety in libc crypt function calls on multi-threaded systems, leading to race conditions. This allows remote attackers to overwrite internal program memory and potentially gain system access.
Recommendations For PHP versions 4.x through 5.2.0, update to version 5.2.1 or later to ensure thread safety for libc crypt function calls and prevent potential system access by remote attackers.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2844

Affected Products

Php