Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-4661
HistorySep 04, 2007 - 12:00 a.m.

CVE-2007-4661

2007-09-0400:00:00
ubuntu.com
ubuntu.com
18

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.258

Percentile

96.7%

The chunk_split function in string.c in PHP 5.2.3 does not properly
calculate the needed buffer size due to precision loss when performing
integer arithmetic with floating point numbers, which has unknown attack
vectors and impact, possibly resulting in a heap-based buffer overflow.
NOTE: this is due to an incomplete fix for CVE-2007-2872.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchphp5< 5.1.2-1ubuntu3.10UNKNOWN
ubuntu6.10noarchphp5< 5.1.6-1ubuntu2.7UNKNOWN
ubuntu7.04noarchphp5< 5.2.1-0ubuntu1.5UNKNOWN
ubuntu7.10noarchphp5< 5.2.3-1ubuntu6.1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.258

Percentile

96.7%