CVE-2008-2829
published 2008-06-23CVE-2008-2829: php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash)…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.27%
91.6th percentile
php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| php | php | <= 4.4.9 | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2008-07-23·CVSS 5.0
CVE-2007-4782 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: PHP vulnerabilities
It was discovered that PHP did not properly check the length of the
string parameter to the fnmatch function. An attacker could cause a
denial of service in the PHP interpreter if a script passed untrusted
input to the fnmatch function. (CVE-2007-4782)
Maksymilian Arciemowicz discovered a flaw in the cURL library that
allowed safe_mode and open_basedir restrictions to be bypassed. If a
PHP application were tricked into processing a bad file:// request,
an attacker could read arbitrary files. (CVE-2007-4850)
Rasmus Lerdorf discovered that the htmlentities and htmlspecialchars
functions did not correctly stop when handling partial multibyte
sequences. A remote attacker could exploit this to read certain areas
of memory, possibly gai
Red Hat
php: ext/imap legacy routine buffer overflow
vendor_redhat·2007-10-05·CVSS 5.0
CVE-2008-2829 [MEDIUM] php: ext/imap legacy routine buffer overflow
php: ext/imap legacy routine buffer overflow
php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.
Statement: Not vulnerable. This issue did not affect the versions of PHP as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5. For more details see:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-2829
GHSA
GHSA-j7wp-2pxv-m6g9: php_imap
ghsa_unreviewed·2022-05-01
CVE-2008-2829 [MEDIUM] CWE-119 GHSA-j7wp-2pxv-m6g9: php_imap
php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.
No detection rules found.
No public exploits indexed.
http://bugs.php.net/bug.php?id=42862http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.htmlhttp://marc.info/?l=bugtraq&m=124654546101607&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://osvdb.org/46641http://secunia.com/advisories/31200http://secunia.com/advisories/32746http://secunia.com/advisories/35074http://secunia.com/advisories/35306http://secunia.com/advisories/35650http://security.gentoo.org/glsa/glsa-200811-05.xmlhttp://support.apple.com/kb/HT3549http://wiki.rpath.com/Advisories:rPSA-2009-0035http://www.mandriva.com/security/advisories?name=MDVSA-2008:126http://www.mandriva.com/security/advisories?name=MDVSA-2008:127http://www.mandriva.com/security/advisories?name=MDVSA-2008:128http://www.openwall.com/lists/oss-security/2008/06/19/6http://www.openwall.com/lists/oss-security/2008/06/24/2http://www.securityfocus.com/archive/1/501376/100/0/threadedhttp://www.securityfocus.com/bid/29829http://www.ubuntu.com/usn/usn-628-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297https://bugs.gentoo.org/show_bug.cgi?id=221969https://exchange.xforce.ibmcloud.com/vulnerabilities/43357https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.htmlhttp://bugs.php.net/bug.php?id=42862http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.htmlhttp://marc.info/?l=bugtraq&m=124654546101607&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://osvdb.org/46641http://secunia.com/advisories/31200http://secunia.com/advisories/32746http://secunia.com/advisories/35074http://secunia.com/advisories/35306http://secunia.com/advisories/35650http://security.gentoo.org/glsa/glsa-200811-05.xmlhttp://support.apple.com/kb/HT3549http://wiki.rpath.com/Advisories:rPSA-2009-0035http://www.mandriva.com/security/advisories?name=MDVSA-2008:126http://www.mandriva.com/security/advisories?name=MDVSA-2008:127http://www.mandriva.com/security/advisories?name=MDVSA-2008:128http://www.openwall.com/lists/oss-security/2008/06/19/6http://www.openwall.com/lists/oss-security/2008/06/24/2http://www.securityfocus.com/archive/1/501376/100/0/threadedhttp://www.securityfocus.com/bid/29829http://www.ubuntu.com/usn/usn-628-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297https://bugs.gentoo.org/show_bug.cgi?id=221969https://exchange.xforce.ibmcloud.com/vulnerabilities/43357https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html
2008-06-23
Published