PT-2007-4176 · Php+1 · Php+1

Published

2007-06-04

·

Updated

2023-02-13

·

CVE-2007-2872

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.2.3 PHP versions prior to 4.4.8
Description The issue is related to multiple integer overflows in the chunk split function. This can be exploited by remote attackers to cause a denial of service (crash) or execute arbitrary code via the chunks, srclen, and chunklen arguments.
Recommendations For PHP versions prior to 5.2.3, update to version 5.2.3 or later. For PHP versions prior to 4.4.8, update to version 4.4.8 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2007-2872
HPSBUX02262
HPSBUX02308
HPSBUX02332
RHSA-2007:0888
RHSA-2007:0889
RHSA-2007:0890
RHSA-2007:0891
RHSA-2007_0890

Affected Products

Php
Red Hat