Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-1325
HistoryMar 07, 2007 - 12:00 a.m.

CVE-2007-1325

2007-03-0700:00:00
ubuntu.com
ubuntu.com
8

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.044

Percentile

92.4%

The PMA_ArrayWalkRecursive function in libraries/common.lib.php in
phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by
users, which allows context-dependent attackers to cause a denial of
service (web server crash) via an array with many dimensions. NOTE: it
could be argued that this vulnerability is caused by a problem in PHP
(CVE-2006-1549) and the proper fix should be in PHP; if so, then this
should not be treated as a vulnerability in phpMyAdmin.

Notes

Author Note
wgrant PMASA-2007-3
OSVersionArchitecturePackageVersionFilename
ubuntu7.04noarchphpmyadmin< 2.9.1.1-2ubuntu1UNKNOWN

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.044

Percentile

92.4%