CVE-2007-1887
published 2007-04-06CVE-2007-1887: Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.75%
90.9th percentile
Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqlite_udf_decode_binary function with a 0x01 character.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| php | php | >= 4.0 < 4.4.5 | 4.4.5 |
| php | php | >= 5.0.0 < 5.2.3 | 5.2.3 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2007-04-27·CVSS 5.0
CVE-2007-1888 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: PHP vulnerabilities
Stefan Esser discovered multiple vulnerabilities in the "Month of PHP
bugs".
The substr_compare() function did not sufficiently verify its length
argument. This might be exploited to read otherwise unaccessible
memory, which might lead to information disclosure. (CVE-2007-1375)
The shared memory (shmop) functions did not verify resource types,
thus they could be called with a wrong resource type that might
contain user supplied data. This could be exploited to read and write
arbitrary memory addresses of the PHP interpreter. This issue does
not affect Ubuntu 7.04. (CVE-2007-1376)
The php_binary handler of the session extension was missing a boundary
check. When unserializing overly long variable names this could be
exploited to r
Red Hat
CVE-2007-1887: Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4
vendor_redhat·CVSS 7.5
CVE-2007-1887 [HIGH] CVE-2007-1887: Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4
Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqlite_udf_decode_binary function with a 0x01 character.
Statement: Not vulnerable. These issues did not affect the versions of PHP as shipped with Red Hat Enterprise Linux 2.1, 3, 4, 5, Stronghold 4.0, or Red Hat Application Stack 1.
GHSA
GHSA-7fcm-v46p-r75h: Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4
ghsa_unreviewed·2022-05-01
CVE-2007-1887 [HIGH] CWE-120 GHSA-7fcm-v46p-r75h: Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4
Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqlite_udf_decode_binary function with a 0x01 character.
No detection rules found.
No public exploits indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795http://secunia.com/advisories/24909http://secunia.com/advisories/25057http://secunia.com/advisories/25062http://secunia.com/advisories/27037http://secunia.com/advisories/27102http://secunia.com/advisories/27110http://www.debian.org/security/2007/dsa-1283http://www.gentoo.org/security/en/glsa/glsa-200710-02.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:088http://www.mandriva.com/security/advisories?name=MDKSA-2007:089http://www.php-security.org/MOPB/MOPB-41-2007.htmlhttp://www.php.net/releases/5_2_1.phphttp://www.php.net/releases/5_2_3.phphttp://www.securityfocus.com/bid/23235http://www.ubuntu.com/usn/usn-455-1http://www.vupen.com/english/advisories/2007/2016http://www.vupen.com/english/advisories/2007/3386https://exchange.xforce.ibmcloud.com/vulnerabilities/33766https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5348https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795http://secunia.com/advisories/24909http://secunia.com/advisories/25057http://secunia.com/advisories/25062http://secunia.com/advisories/27037http://secunia.com/advisories/27102http://secunia.com/advisories/27110http://www.debian.org/security/2007/dsa-1283http://www.gentoo.org/security/en/glsa/glsa-200710-02.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:088http://www.mandriva.com/security/advisories?name=MDKSA-2007:089http://www.php-security.org/MOPB/MOPB-41-2007.htmlhttp://www.php.net/releases/5_2_1.phphttp://www.php.net/releases/5_2_3.phphttp://www.securityfocus.com/bid/23235http://www.ubuntu.com/usn/usn-455-1http://www.vupen.com/english/advisories/2007/2016http://www.vupen.com/english/advisories/2007/3386https://exchange.xforce.ibmcloud.com/vulnerabilities/33766https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5348https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html
2007-04-06
Published