Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-4657

Опубликовано: 04 сент. 2007
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

edgy

ignored

end of life, was needed
feisty

DNE

gutsy

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

released

4.4.8

Показывать по

РелизСтатусПримечание
dapper

released

5.1.2-1ubuntu3.10
devel

not-affected

5.2.4-2ubuntu3
edgy

released

5.1.6-1ubuntu2.7
feisty

released

5.2.1-0ubuntu1.5
gutsy

released

5.2.3-1ubuntu6.1
hardy

not-affected

5.2.4-2ubuntu3
intrepid

not-affected

5.2.4-2ubuntu3
jaunty

not-affected

5.2.4-2ubuntu3
karmic

not-affected

5.2.4-2ubuntu3
upstream

released

5.2.4

Показывать по

EPSS

Процентиль: 82%
0.01774
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
почти 18 лет назад

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.

debian
почти 18 лет назад

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2 ...

github
около 3 лет назад

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.

EPSS

Процентиль: 82%
0.01774
Низкий

7.5 High

CVSS2