CVE-2007-0988
The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause…
Does this matter?
Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.
Description
The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-bit arguments to be used after the check for a negative value, as demonstrated by an "a:2147483649:{" argument.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- php/php · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.ascBroken Link
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=228858Issue Tracking, Third Party Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01056506Broken Link
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01086137Broken Link
- http://osvdb.org/32762Broken Link
- http://rhn.redhat.com/errata/RHSA-2007-0089.htmlThird Party Advisory
- http://secunia.com/advisories/24195Third Party Advisory
- http://secunia.com/advisories/24217Third Party Advisory
- http://secunia.com/advisories/24236Third Party Advisory
- http://secunia.com/advisories/24248Third Party Advisory
- http://secunia.com/advisories/24284Third Party Advisory
- http://secunia.com/advisories/24295Third Party Advisory
- http://secunia.com/advisories/24322Third Party Advisory
- http://secunia.com/advisories/24419Third Party Advisory
- http://secunia.com/advisories/24421Third Party Advisory
- http://secunia.com/advisories/24432Third Party Advisory
- http://secunia.com/advisories/24606Third Party Advisory
- http://secunia.com/advisories/24642Third Party Advisory
- http://secunia.com/advisories/25056Third Party Advisory
- http://secunia.com/advisories/25423Third Party Advisory
- http://secunia.com/advisories/25850Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200703-21.xmlThird Party Advisory
- http://securityreason.com/securityalert/2315Third Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2007-101.htmThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2007-136.htmThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:048Third Party Advisory
- http://www.novell.com/linux/security/advisories/2007_32_php.htmlBroken Link
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.htmlThird Party Advisory
- http://www.php-security.org/MOPB/MOPB-05-2007.htmlThird Party Advisory
- http://www.php.net/releases/5_2_1.phpPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.