CVE-2006-4482

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 31 Aug 2006, 21:00
Last modified:07 Aug 2024, 19:14

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
4.1% LOW
4% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

31 Aug 2006, 21:00
Published
Vulnerability first disclosed
07 Aug 2024, 19:14
Last Modified
Vulnerability information updated

Description

Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.

CVSS Metrics

  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 4.10% Percentile: 89%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • canonicalubuntu_linux

    5.04 | 5.10 | 6.06

  • debiandebian_linux

    3.1

  • UnknownPHP

    < 5.1.5

References (30)