CVE-2007-4782

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 10 Sept 2007, 21:00
Last modified:07 Aug 2024, 15:08

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
2.91% LOW
3% probability -0.37%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

10 Sept 2007, 21:00
Published
Vulnerability first disclosed
07 Aug 2024, 15:08
Last Modified
Vulnerability information updated

Description

PHP before 5.2.3 allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the pattern parameter to the glob function; or (2) a long string in the string parameter to the fnmatch function, accompanied by a pattern parameter value with undefined characteristics, as demonstrated by a "*[1]e" value. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 2.91% Percentile: 87%

Techniques & Countermeasures

  • CWE-94Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Affected Systems

  • UnknownPHP

    ≤ 5.2.3

References (23)