CVE-2007-0906

CWE-119Buffer Overflow16 documents6 sources
Severity
7.5HIGH
EPSS
2.2%
top 15.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 13
Latest updateMay 3

Description

Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions. NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885). NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDphp/php67 versions+66
NVDtrustix/secure_linux2.2, 3.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f8vv-w522-3v4v: Multiple buffer overflows in PHP before 52022-05-03
CVEList
CVE-2007-0906: Multiple buffer overflows in PHP before 52007-02-13

📋Vendor Advisories

7
Ubuntu
PHP vulnerabilities2007-02-22
Red Hat
security flaw2007-02-14
Red Hat
php session extension information leak2007-02-14
Red Hat
php imap_mail_compose() buffer overflow via type.parameters2007-02-14
Red Hat
php php_stream_filter_create overflow

💬Community

6
Bugzilla
CVE-2007-0906 security flaw2018-08-16
Bugzilla
CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)2007-02-23
Bugzilla
CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)2007-02-20
Bugzilla
CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)2007-02-20
Bugzilla
CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)2007-02-16
CVE-2007-0906 (HIGH CVSS 7.5) | Multiple buffer overflows in PHP be | cvebase.io