CVE-2007-2872
Last modified
CVE-2007-2872 is a vulnerability of currently unknown severity. Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.. EPSS estimates a 8.88% chance of exploitation in the next 30 days.
Description
Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | <= 4.4.7 |
| Php | Php | 5.0.0 |
| Php | Php | 5.0.1 |
| Php | Php | 5.0.2 |
| Php | Php | 5.0.3 |
| Php | Php | 5.0.4 |
| Php | Php | 5.0.5 |
| Php | Php | 5.1.0 |
| Php | Php | 5.1.1 |
| Php | Php | 5.1.2 |
| Php | Php | 5.1.3 |
| Php | Php | 5.1.4 |
| Php | Php | 5.1.5 |
| Php | Php | 5.1.6 |
| Php | Php | 5.2.0 |
| Php | Php | 5.2.1 |
| Php | Php | 5.2.2 |
References
- http://rhn.redhat.com/errata/RHSA-2007-0889.htmlVendor Advisory
- http://secunia.com/advisories/25456Vendor Advisory
- http://secunia.com/advisories/25535Vendor Advisory
- http://secunia.com/advisories/26048Vendor Advisory
- http://secunia.com/advisories/26231Vendor Advisory
- http://secunia.com/advisories/26838Vendor Advisory
- http://secunia.com/advisories/26871Vendor Advisory
- http://secunia.com/advisories/26895Vendor Advisory
- http://secunia.com/advisories/26930Vendor Advisory
- http://secunia.com/advisories/26967Vendor Advisory
- http://secunia.com/advisories/27037Vendor Advisory
- http://secunia.com/advisories/27102Vendor Advisory
- http://secunia.com/advisories/27110Vendor Advisory
- http://secunia.com/advisories/27351Vendor Advisory
- http://secunia.com/advisories/27377Vendor Advisory
- http://secunia.com/advisories/27545Vendor Advisory
- http://secunia.com/advisories/27864Vendor Advisory
- http://secunia.com/advisories/28318Vendor Advisory
- http://secunia.com/advisories/28658Vendor Advisory
- http://secunia.com/advisories/30040Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0888.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0890.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2007-0889.htmlVendor Advisory
- http://secunia.com/advisories/25456Vendor Advisory
- http://secunia.com/advisories/25535Vendor Advisory
- http://secunia.com/advisories/26048Vendor Advisory
- http://secunia.com/advisories/26231Vendor Advisory
- http://secunia.com/advisories/26838Vendor Advisory
- http://secunia.com/advisories/26871Vendor Advisory
- http://secunia.com/advisories/26895Vendor Advisory
- http://secunia.com/advisories/26930Vendor Advisory
- http://secunia.com/advisories/26967Vendor Advisory
- http://secunia.com/advisories/27037Vendor Advisory
- http://secunia.com/advisories/27102Vendor Advisory
- http://secunia.com/advisories/27110Vendor Advisory
- http://secunia.com/advisories/27351Vendor Advisory
- http://secunia.com/advisories/27377Vendor Advisory
- http://secunia.com/advisories/27545Vendor Advisory
- http://secunia.com/advisories/27864Vendor Advisory
- http://secunia.com/advisories/28318Vendor Advisory
- http://secunia.com/advisories/28658Vendor Advisory
- http://secunia.com/advisories/30040Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0888.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0890.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2872?
How severe is CVE-2007-2872?
How do I fix CVE-2007-2872?
Are you affected by CVE-2007-2872?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
