CVE-2007-1286
medium · 6.8Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.
6.8
CVSS
40.4%
EPSS (exploit prob.)
99th
EPSS percentile
2007-03-06
Published
AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| php | php | <= 4.4.4 |
Check a specific version with /api/v1/cve/match.
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01056506
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01086137
- http://rhn.redhat.com/errata/RHSA-2007-0154.html
- http://rhn.redhat.com/errata/RHSA-2007-0155.html
- http://rhn.redhat.com/errata/RHSA-2007-0163.html
- http://secunia.com/advisories/24419
- http://secunia.com/advisories/24606
- http://secunia.com/advisories/24910
- http://secunia.com/advisories/24924
- http://secunia.com/advisories/24941
- http://secunia.com/advisories/24945
- http://secunia.com/advisories/25025
- http://secunia.com/advisories/25062
- http://secunia.com/advisories/25423
- http://secunia.com/advisories/25445
- http://secunia.com/advisories/25850
- http://security.gentoo.org/glsa/glsa-200703-21.xml
- http://security.gentoo.org/glsa/glsa-200705-19.xml
- http://www.debian.org/security/2007/dsa-1282
- http://www.debian.org/security/2007/dsa-1283
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:087
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:088
- http://www.osvdb.org/32771
- http://www.php-security.org/MOPB/MOPB-04-2007.html
- http://www.securityfocus.com/archive/1/466166/100/0/threaded
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-1286