CVE-2007-1376
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.0%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 10.03% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- php/php
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24606
- http://secunia.com/advisories/25056
- http://secunia.com/advisories/25057
- http://secunia.com/advisories/25062
- http://security.gentoo.org/glsa/glsa-200703-21.xml
- http://www.debian.org/security/2007/dsa-1283
- http://www.novell.com/linux/security/advisories/2007_32_php.html
- http://www.osvdb.org/32781
- http://www.php-security.org/MOPB/MOPB-15-2007.htmlExploit
- http://www.securityfocus.com/bid/22862Exploit
- http://www.ubuntu.com/usn/usn-455-1
- https://www.exploit-db.com/exploits/3426
- https://www.exploit-db.com/exploits/3427
- http://secunia.com/advisories/24606
- http://secunia.com/advisories/25056
- http://secunia.com/advisories/25057
- http://secunia.com/advisories/25062
- http://security.gentoo.org/glsa/glsa-200703-21.xml
- http://www.debian.org/security/2007/dsa-1283
- http://www.novell.com/linux/security/advisories/2007_32_php.html
- http://www.osvdb.org/32781
- http://www.php-security.org/MOPB/MOPB-15-2007.htmlExploit
- http://www.securityfocus.com/bid/22862Exploit
- http://www.ubuntu.com/usn/usn-455-1
- https://www.exploit-db.com/exploits/3426
- https://www.exploit-db.com/exploits/3427
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.