PT-2007-5819 · Php · Php

Published

2007-09-04

·

Updated

2018-10-03

·

CVE-2007-4661

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHP version 5.2.3
Description: The issue is related to the chunk split function in string.c, which does not properly calculate the needed buffer size due to precision loss when performing integer arithmetic with floating point numbers. This could possibly result in a heap-based buffer overflow. The attack vectors and impact are unknown.
Recommendations: For PHP version 5.2.3, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4661
RHSA-2007:0917

Affected Products

Php