CVE-2007-1864
published 2007-05-09CVE-2007-1864: Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.92%
85.5th percentile
Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| php | php | < 4.4.7 | 4.4.7 |
| php | php | 5.1.0 – 5.1.6 | — |
| php | php | >= 5.2.0 < 5.2.2 | 5.2.2 |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c645-h8hj-wvjj: Buffer overflow in the bundled libxmlrpc library in PHP before 4
ghsa_unreviewed·2022-05-01
CVE-2007-1864 [HIGH] CWE-119 GHSA-c645-h8hj-wvjj: Buffer overflow in the bundled libxmlrpc library in PHP before 4
Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2007-07-17·CVSS 7.5
CVE-2007-1864 [HIGH] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: PHP vulnerabilities
It was discovered that the PHP xmlrpc extension did not correctly check
heap memory allocation sizes. A remote attacker could send a specially
crafted request to a PHP application using xmlrpc and execute arbitrary
code as the Apache user. (CVE-2007-1864)
Stefan Esser discovered a flaw in the random number initialization of the
PHP SOAP extension. This could lead to remote attackers being able to
predict certain elements of the authentication mechanism. (CVE-2007-2728)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
php libxmlrpc library overflow
vendor_redhat·2007-05-03·CVSS 7.5
CVE-2007-1864 [HIGH] php libxmlrpc library overflow
php libxmlrpc library overflow
Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-1864 php libxmlrpc library overflow
bugzilla·2007-05-04·CVSS 7.5
CVE-2007-1864 [HIGH] CVE-2007-1864 php libxmlrpc library overflow
CVE-2007-1864 php libxmlrpc library overflow
The PHP announcement on 20070503 included an issue which is a remotely
triggerable heap buffer overflow inside the bundled libxmlrpc library. Note
that this is the C xmlrpc library extension and most PHP applications
implementing XMLRPC would use the native-PHP xmlrpc code which is not affected
by this issue.
Discussion:
text "A heap buffer overflow flaw was found in the PHP 'xmlrpc' extension. A
PHP script which implements an XML-RPC server using this extension
could allow a remote attacker to execute arbitrary code as the 'apache'
user. Note that this flaw does not affect PHP applications using the
pure-PHP XML_RPC class provided in /usr/share/pear. (CVE-2007-1864) "
Bugzilla
CVE-2007-1864 various PHP security issues (CVE-2007-2509 CVE-2007-2510)
bugzilla·2007-05-04·CVSS 7.5
CVE-2007-1864 [HIGH] CVE-2007-1864 various PHP security issues (CVE-2007-2509 CVE-2007-2510)
CVE-2007-1864 various PHP security issues (CVE-2007-2509 CVE-2007-2510)
Please see linked "blocks" bugs for individual issues
Discussion:
*** This bug has been marked as a duplicate of 239015 ***
Bugzilla
CVE-2007-1864 various PHP security issues (CVE-2007-2509)
bugzilla·2007-05-04·CVSS 7.5
CVE-2007-1864 [HIGH] CVE-2007-1864 various PHP security issues (CVE-2007-2509)
CVE-2007-1864 various PHP security issues (CVE-2007-2509)
Please see linked "blocks" bugs for individual issues
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2007-0349.html
Bugzilla
CVE-2007-1864: various PHP security issues (CVE-2007-2509 CVE-2007-2510)
bugzilla·2007-05-04·CVSS 7.5
CVE-2007-1864 [HIGH] CVE-2007-1864: various PHP security issues (CVE-2007-2509 CVE-2007-2510)
CVE-2007-1864: various PHP security issues (CVE-2007-2509 CVE-2007-2510)
+++ This bug was initially created as a clone of Bug #239016 +++
Please see linked "blocks" bugs for individual issues
Discussion:
*** This bug has been marked as a duplicate of 239020 ***
Bugzilla
CVE-2007-1864 various PHP security issues (CVE-2007-2509 CVE-2007-2510)
bugzilla·2007-05-04·CVSS 7.5
CVE-2007-1864 [HIGH] CVE-2007-1864 various PHP security issues (CVE-2007-2509 CVE-2007-2510)
CVE-2007-1864 various PHP security issues (CVE-2007-2509 CVE-2007-2510)
Please see linked "blocks" bugs for individual issues
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2007-0355.html
---
*** Bug 239026 has been marked as a duplicate of this bug. ***
Bugzilla
CVE-2007-1864 various PHP security issues (CVE-2007-2509 CVE-2007-2510)
bugzilla·2007-05-04·CVSS 7.5
CVE-2007-1864 [HIGH] CVE-2007-1864 various PHP security issues (CVE-2007-2509 CVE-2007-2510)
CVE-2007-1864 various PHP security issues (CVE-2007-2509 CVE-2007-2510)
Please see linked "blocks" bugs for individual issues
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2007-0348.html
---
*** Bug 239016 has been marked as a duplicate of this bug. ***
http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.htmlhttp://osvdb.org/34674http://secunia.com/advisories/25187http://secunia.com/advisories/25191http://secunia.com/advisories/25255http://secunia.com/advisories/25445http://secunia.com/advisories/25660http://secunia.com/advisories/25938http://secunia.com/advisories/25945http://secunia.com/advisories/26048http://secunia.com/advisories/26102http://secunia.com/advisories/27377http://security.gentoo.org/glsa/glsa-200705-19.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2007-231.htmhttp://us2.php.net/releases/4_4_7.phphttp://us2.php.net/releases/5_2_2.phphttp://www.debian.org/security/2007/dsa-1330http://www.debian.org/security/2007/dsa-1331http://www.mandriva.com/security/advisories?name=MDKSA-2007:102http://www.mandriva.com/security/advisories?name=MDKSA-2007:103http://www.redhat.com/support/errata/RHSA-2007-0349.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0355.htmlhttp://www.securityfocus.com/bid/23813http://www.securitytracker.com/id?1018024http://www.trustix.org/errata/2007/0017/http://www.ubuntu.com/usn/usn-485-1http://www.vupen.com/english/advisories/2007/2187https://issues.rpath.com/browse/RPL-1693https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11257https://rhn.redhat.com/errata/RHSA-2007-0348.htmlhttp://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.htmlhttp://osvdb.org/34674http://secunia.com/advisories/25187http://secunia.com/advisories/25191http://secunia.com/advisories/25255http://secunia.com/advisories/25445http://secunia.com/advisories/25660http://secunia.com/advisories/25938http://secunia.com/advisories/25945http://secunia.com/advisories/26048http://secunia.com/advisories/26102http://secunia.com/advisories/27377http://security.gentoo.org/glsa/glsa-200705-19.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2007-231.htmhttp://us2.php.net/releases/4_4_7.phphttp://us2.php.net/releases/5_2_2.phphttp://www.debian.org/security/2007/dsa-1330http://www.debian.org/security/2007/dsa-1331http://www.mandriva.com/security/advisories?name=MDKSA-2007:102http://www.mandriva.com/security/advisories?name=MDKSA-2007:103http://www.redhat.com/support/errata/RHSA-2007-0349.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0355.htmlhttp://www.securityfocus.com/bid/23813http://www.securitytracker.com/id?1018024http://www.trustix.org/errata/2007/0017/http://www.ubuntu.com/usn/usn-485-1http://www.vupen.com/english/advisories/2007/2187https://issues.rpath.com/browse/RPL-1693https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11257https://rhn.redhat.com/errata/RHSA-2007-0348.html
2007-05-09
Published