PT-2007-5819 · Php · Php
Published
2007-09-04
·
Updated
2018-10-03
·
CVE-2007-4661
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PHP version 5.2.3
Description:
The issue is related to the chunk split function in string.c, which does not properly calculate the needed buffer size due to precision loss when performing integer arithmetic with floating point numbers. This could possibly result in a heap-based buffer overflow. The attack vectors and impact are unknown.
Recommendations:
For PHP version 5.2.3, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php