Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-1883
HistoryApr 06, 2007 - 12:00 a.m.

CVE-2007-1883

2007-04-0600:00:00
ubuntu.com
ubuntu.com
21

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

EPSS

0.004

Percentile

73.5%

PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent
attackers to read arbitrary memory locations via an interruption that
triggers a user space error handler that changes a parameter to an
arbitrary pointer, as demonstrated via the iptcembed function, which calls
certain convert_to_* functions with its input parameters.

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

EPSS

0.004

Percentile

73.5%