CVE-2007-1381
Last modified
CVE-2007-1381 is a vulnerability of currently unknown severity. The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to execute arbitrary code via a WDDX packet with a malformed overlap of a STRING element, which triggers a buffer overflow.. EPSS estimates a 9.07% chance of exploitation in the next 30 days.
Description
The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to execute arbitrary code via a WDDX packet with a malformed overlap of a STRING element, which triggers a buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | 5.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1381?
How severe is CVE-2007-1381?
How do I fix CVE-2007-1381?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1375Integer overflow in the substr_compare function in PHP 5.2.1…
- CVE-2007-1376The shmop functions in PHP before 4.4.5, and before 5.2.1 in…
- CVE-2007-1377AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla …
- CVE-2007-1378The ovrimos_longreadlen function in the Ovrimos extension fo…
- CVE-2007-1379The ovrimos_close function in the Ovrimos extension for PHP …
- CVE-2007-1380The php_binary serialization handler in the session extensio…
- CVE-2007-1382The PHP COM extensions for PHP on Windows systems allow cont…
- CVE-2007-1383Integer overflow in the 16 bit variable reference counter in…9.8
- CVE-2007-1384Directory traversal vulnerability in torrent.cpp in KTorrent…
- CVE-2007-1385chunkcounter.cpp in KTorrent before 2.1.2 allows remote atta…
- CVE-2007-1387The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MP…
- CVE-2007-1388The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c …
Are you affected by CVE-2007-1381?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
