Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
Severity
7.5HIGH
EPSS
6.8%
top 8.67%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 6
Latest updateMay 1

Description

The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

NVDphp/php4.0.04.4.7+1
NVDnovell/suse_linux10.0, 10.1+1
NVDredhat/enterprise_linux_server2.0, 3.0, 4.0+2

Also affects: Ubuntu Linux 7.10

🔴Vulnerability Details

2
GHSA
GHSA-jhxw-fqxp-j75j: The Zend Engine in PHP 42022-05-01
CVEList
CVE-2007-1285: The Zend Engine in PHP 42007-03-06

💥Exploits & PoCs

1
Exploit-DB
PHP 3/4/5 - ZendEngine Variable Destruction Remote Denial of Service2007-03-01

📋Vendor Advisories

3
Ubuntu
PHP vulnerabilities2007-11-29
Red Hat
php malformed cookie handling2007-08-30
Red Hat
security flaw2007-03-01

💬Community

4
Bugzilla
CVE-2007-1285 security flaw2018-08-16
Bugzilla
CVE-2007-1285 Multiple PHP issues (CVE-2007-1286, CVE-2007-1711)2007-04-05
Bugzilla
CVE-2007-1285 PHP Variable Destructor Deep Recursion Stack Overflow2007-03-09
Bugzilla
CVE-2007-1285 "Month of PHP Bugs" security issues (CVE-2007-1286 CVE-2007-1583 CVE-2007-1711 CVE-2007-1718)2007-03-01
CVE-2007-1285 (HIGH CVSS 7.5) | The Zend Engine in PHP 4.x before 4 | cvebase.io