CVE-2007-2872
published 2007-06-04CVE-2007-2872: Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash)…
PriorityP339medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
8.88%
94.6th percentile
Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| php | php | <= 4.4.7 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_ubuntu7.5HIGH
vendor_redhat6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP regression
vendor_ubuntu·2007-12-03·CVSS 7.5
[HIGH] PHP regression
Title: PHP regression
Summary: PHP regression
USN-549-1 fixed vulnerabilities in PHP. However, some upstream changes
were incomplete, which caused crashes in certain situations with Ubuntu
7.10. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the wordwrap function did not correctly
check lengths. Remote attackers could exploit this to cause
a crash or monopolize CPU resources, resulting in a denial of
service. (CVE-2007-3998)
Integer overflows were discovered in the strspn and strcspn functions.
Attackers could exploit this to read arbitrary areas of memory, possibly
gaining access to sensitive information. (CVE-2007-4657)
Stanislav Malyshev discovered that money_format function did not correctly
handle certain tok
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2007-11-29·CVSS 7.5
CVE-2007-1285 [HIGH] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: PHP vulnerabilities
It was discovered that the wordwrap function did not correctly
check lengths. Remote attackers could exploit this to cause
a crash or monopolize CPU resources, resulting in a denial of
service. (CVE-2007-3998)
Integer overflows were discovered in the strspn and strcspn functions.
Attackers could exploit this to read arbitrary areas of memory, possibly
gaining access to sensitive information. (CVE-2007-4657)
Stanislav Malyshev discovered that money_format function did not correctly
handle certain tokens. If a PHP application were tricked into processing
a bad format string, a remote attacker could execute arbitrary code with
application privileges. (CVE-2007-4658)
It was discovered that the php_openssl_make_REQ function did not
co
Red Hat
php size calculation in chunk_split
vendor_redhat·2007-08-30·CVSS 6.8
CVE-2007-4661 [MEDIUM] php size calculation in chunk_split
php size calculation in chunk_split
The chunk_split function in string.c in PHP 5.2.3 does not properly calculate the needed buffer size due to precision loss when performing integer arithmetic with floating point numbers, which has unknown attack vectors and impact, possibly resulting in a heap-based buffer overflow. NOTE: this is due to an incomplete fix for CVE-2007-2872.
Red Hat
php chunk_split integer overflow
vendor_redhat·2007-06-01·CVSS 6.8
CVE-2007-2872 [MEDIUM] CWE-190 php chunk_split integer overflow
php chunk_split integer overflow
Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.
Statement: The Red Hat Product Security has rated this issue as having moderate security impact, a future update may address this flaw.
GHSA
GHSA-gm64-4hqj-9wvv: The chunk_split function in string
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2007-4661 [MEDIUM] CWE-119 GHSA-gm64-4hqj-9wvv: The chunk_split function in string
The chunk_split function in string.c in PHP 5.2.3 does not properly calculate the needed buffer size due to precision loss when performing integer arithmetic with floating point numbers, which has unknown attack vectors and impact, possibly resulting in a heap-based buffer overflow. NOTE: this is due to an incomplete fix for CVE-2007-2872.
GHSA
GHSA-vg29-wjx8-q6g3: Multiple integer overflows in the chunk_split function in PHP 5 before 5
ghsa_unreviewed·2022-05-01
CVE-2007-2872 [MEDIUM] GHSA-vg29-wjx8-q6g3: Multiple integer overflows in the chunk_split function in PHP 5 before 5
Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.
No detection rules found.
No writeups or analysis indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.htmlhttp://osvdb.org/36083http://rhn.redhat.com/errata/RHSA-2007-0889.htmlhttp://secunia.com/advisories/25456http://secunia.com/advisories/25535http://secunia.com/advisories/26048http://secunia.com/advisories/26231http://secunia.com/advisories/26838http://secunia.com/advisories/26871http://secunia.com/advisories/26895http://secunia.com/advisories/26930http://secunia.com/advisories/26967http://secunia.com/advisories/27037http://secunia.com/advisories/27102http://secunia.com/advisories/27110http://secunia.com/advisories/27351http://secunia.com/advisories/27377http://secunia.com/advisories/27545http://secunia.com/advisories/27864http://secunia.com/advisories/28318http://secunia.com/advisories/28658http://secunia.com/advisories/28750http://secunia.com/advisories/28936http://secunia.com/advisories/30040http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.482863http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.335136http://support.avaya.com/elmodocs2/security/ASA-2007-449.htmhttp://www.gentoo.org/security/en/glsa/glsa-200710-02.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:187http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.020.htmlhttp://www.php.net/ChangeLog-4.phphttp://www.php.net/releases/4_4_8.phphttp://www.php.net/releases/5_2_3.phphttp://www.redhat.com/support/errata/RHSA-2007-0888.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0890.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0891.htmlhttp://www.sec-consult.com/291.htmlhttp://www.securityfocus.com/archive/1/470244/100/0/threadedhttp://www.securityfocus.com/archive/1/491693/100/0/threadedhttp://www.securityfocus.com/bid/24261http://www.securitytracker.com/id?1018186http://www.trustix.org/errata/2007/0023/http://www.ubuntu.com/usn/usn-549-2http://www.vupen.com/english/advisories/2007/2061http://www.vupen.com/english/advisories/2007/3386http://www.vupen.com/english/advisories/2008/0059http://www.vupen.com/english/advisories/2008/0398https://exchange.xforce.ibmcloud.com/vulnerabilities/39398https://issues.rpath.com/browse/RPL-1693https://issues.rpath.com/browse/RPL-1702https://launchpad.net/bugs/173043https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9424https://usn.ubuntu.com/549-1/https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.htmlhttp://osvdb.org/36083http://rhn.redhat.com/errata/RHSA-2007-0889.htmlhttp://secunia.com/advisories/25456http://secunia.com/advisories/25535http://secunia.com/advisories/26048http://secunia.com/advisories/26231http://secunia.com/advisories/26838http://secunia.com/advisories/26871http://secunia.com/advisories/26895http://secunia.com/advisories/26930http://secunia.com/advisories/26967http://secunia.com/advisories/27037http://secunia.com/advisories/27102http://secunia.com/advisories/27110http://secunia.com/advisories/27351http://secunia.com/advisories/27377http://secunia.com/advisories/27545http://secunia.com/advisories/27864http://secunia.com/advisories/28318http://secunia.com/advisories/28658http://secunia.com/advisories/28750http://secunia.com/advisories/28936http://secunia.com/advisories/30040http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.482863http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.335136http://support.avaya.com/elmodocs2/security/ASA-2007-449.htmhttp://www.gentoo.org/security/en/glsa/glsa-200710-02.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:187http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.020.htmlhttp://www.php.net/ChangeLog-4.phphttp://www.php.net/releases/4_4_8.phphttp://www.php.net/releases/5_2_3.phphttp://www.redhat.com/support/errata/RHSA-2007-0888.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0890.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0891.htmlhttp://www.sec-consult.com/291.htmlhttp://www.securityfocus.com/archive/1/470244/100/0/threadedhttp://www.securityfocus.com/archive/1/491693/100/0/threaded
+ 16 more references
2007-06-04
Published