CVE-2003-0166
Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 14.12% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- php/php
- Source
- cve@mitre.org
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000691
- http://marc.info/?l=bugtraq&m=104869828526885&w=2
- http://marc.info/?l=bugtraq&m=104878100719467&w=2
- http://marc.info/?l=bugtraq&m=104931415307111&w=2
- http://www.securityfocus.com/bid/7197Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/7198Exploit, Vendor Advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000691
- http://marc.info/?l=bugtraq&m=104869828526885&w=2
- http://marc.info/?l=bugtraq&m=104878100719467&w=2
- http://marc.info/?l=bugtraq&m=104931415307111&w=2
- http://www.securityfocus.com/bid/7197Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/7198Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.