Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-2844
HistoryMay 24, 2007 - 12:00 a.m.

CVE-2007-2844

2007-05-2400:00:00
ubuntu.com
ubuntu.com
11

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.03

Percentile

91.0%

PHP 4.x and 5.x before 5.2.1, when running on multi-threaded systems, does
not ensure thread safety for libc crypt function calls using protection
schemes such as a mutex, which creates race conditions that allow remote
attackers to overwrite internal program memory and gain system access.

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.03

Percentile

91.0%