CVE-2003-1303
Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 12.12% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- php/php
- Source
- secalert@redhat.com
References
- http://bugs.php.net/bug.php?id=24150Exploit
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040Patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10346
- http://bugs.php.net/bug.php?id=24150Exploit
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040Patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10346
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.