cbcvebase.
CVE-2007-1285
published 2007-03-06

CVE-2007-1285: The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EXPLOIT
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.

Affected

16 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
novellsuse_linux
novellsuse_linux
phpphp<= 5.2.3
phpphp>= 4.0.0 < 4.4.74.4.7
phpphp>= 5.0.0 < 5.2.25.2.2
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
suselinux_enterprise_server
suselinux_enterprise_server

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd5.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P