PT-2007-4148 · Php · Php
Published
2007-05-24
·
Updated
2018-10-30
·
CVE-2007-2844
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PHP versions 4.x through 5.2.0
Description
The issue arises from the lack of thread safety in libc crypt function calls on multi-threaded systems, leading to race conditions. This allows remote attackers to overwrite internal program memory and potentially gain system access.
Recommendations
For PHP versions 4.x through 5.2.0, update to version 5.2.1 or later to ensure thread safety for libc crypt function calls and prevent potential system access by remote attackers.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php