CVE-2007-1887
Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqlite_udf_decode_binary function with a 0x01 character.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.75% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- php/php · canonical/ubuntu linux · debian/debian linux
- Source
- cve@mitre.org
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795Broken Link
- http://secunia.com/advisories/24909Not Applicable
- http://secunia.com/advisories/25057Not Applicable
- http://secunia.com/advisories/25062Not Applicable
- http://secunia.com/advisories/27037Not Applicable
- http://secunia.com/advisories/27102Not Applicable
- http://secunia.com/advisories/27110Not Applicable
- http://www.debian.org/security/2007/dsa-1283Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200710-02.xmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:088Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:089Broken Link
- http://www.php-security.org/MOPB/MOPB-41-2007.htmlBroken Link, Vendor Advisory
- http://www.php.net/releases/5_2_1.phpRelease Notes, Vendor Advisory
- http://www.php.net/releases/5_2_3.phpRelease Notes, Vendor Advisory
- http://www.securityfocus.com/bid/23235Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-455-1Third Party Advisory
- http://www.vupen.com/english/advisories/2007/2016Permissions Required
- http://www.vupen.com/english/advisories/2007/3386Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33766Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5348Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.htmlMailing List, Third Party Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795Broken Link
- http://secunia.com/advisories/24909Not Applicable
- http://secunia.com/advisories/25057Not Applicable
- http://secunia.com/advisories/25062Not Applicable
- http://secunia.com/advisories/27037Not Applicable
- http://secunia.com/advisories/27102Not Applicable
- http://secunia.com/advisories/27110Not Applicable
- http://www.debian.org/security/2007/dsa-1283Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200710-02.xmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.