CVE-2008-2829

UnknownEPSS 5.27%

Last modified

CVE-2008-2829 is a vulnerability of currently unknown severity. php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.. EPSS estimates a 5.27% chance of exploitation in the next 30 days.

Description

php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.

Metrics

EPSS Probability
5.27%

91.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PhpPhp<= 4.4.9
PhpPhp5.2.5
PhpPhp5.2.6
CanonicalUbuntu Linux6.06
CanonicalUbuntu Linux7.04
CanonicalUbuntu Linux7.10
CanonicalUbuntu Linux8.04

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-2829?
php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.
How severe is CVE-2008-2829?
Severity scoring for CVE-2008-2829 is pending analysis. The EPSS model estimates a 5.27% probability of exploitation in the next 30 days.
How do I fix CVE-2008-2829?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-2829?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST