CVE-2007-1521
Advisory lineage Upstream: 0 Downstream: 4
Downstream
Modified
Published: 20 Mar 2007, 20:00
Last modified:07 Aug 2024, 12:59
Vulnerability Summary
Overall Risk (default)
medium
41/100 CVSS Score
6.8 MEDIUM
v2.0 (nvd)
EPSS Score
16.98% MEDIUM
17% probability +1.72%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected
Timeline
20 Mar 2007, 20:00
Published
Vulnerability first disclosed
07 Aug 2024, 12:59
Last Modified
Vulnerability information updated
Description
Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.
CVSS Metrics
- v2.0•MEDIUM•Score: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 16.98%• Percentile: 95%
Affected Systems
- Unknown•PHP
≤ 5.2.1
References (21)
- http://www.vupen.com/english/advisories/2007/0960
- http://www.vupen.com/english/advisories/2007/2732
- http://secunia.com/advisories/25056
- http://www.debian.org/security/2007/dsa-1283
- http://secunia.com/advisories/24505
- http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
- http://security.gentoo.org/glsa/glsa-200705-19.xml
- http://us2.php.net/releases/4_4_7.php
- http://secunia.com/advisories/25062
- http://www.ubuntu.com/usn/usn-455-1
- http://www.debian.org/security/2007/dsa-1282
- http://us2.php.net/releases/5_2_2.php
- http://docs.info.apple.com/article.html?artnum=306172
- http://www.php-security.org/MOPB/MOPB-22-2007.html
- http://www.securityfocus.com/bid/25159
- http://secunia.com/advisories/25445
- http://secunia.com/advisories/25057
- http://www.novell.com/linux/security/advisories/2007_32_php.html
- http://secunia.com/advisories/25025
- http://www.securityfocus.com/bid/22968
- http://secunia.com/advisories/26235