Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-1990

Опубликовано: 24 апр. 2006
Источник: ubuntu
Приоритет: untriaged
EPSS Низкий
CVSS2: 5

Описание

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

edgy

released

4.4.2-1.1
feisty

DNE

gutsy

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

5.1.2-1ubuntu3.9
devel

released

5.2.3-1ubuntu5
edgy

released

5.1.6-1ubuntu2.6
feisty

released

5.2.1-0ubuntu1.4
gutsy

released

5.2.3-1ubuntu5
hardy

released

5.2.3-1ubuntu5
intrepid

released

5.2.3-1ubuntu5
jaunty

released

5.2.3-1ubuntu5
karmic

released

5.2.3-1ubuntu5
upstream

needs-triage

Показывать по

EPSS

Процентиль: 75%
0.00958
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
около 19 лет назад

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.

nvd
около 19 лет назад

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.

debian
около 19 лет назад

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and ...

github
около 3 лет назад

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.

EPSS

Процентиль: 75%
0.00958
Низкий

5 Medium

CVSS2