CVE-2008-0599

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 05 May 2008, 17:00
Last modified:07 Aug 2024, 07:54

Vulnerability Summary

Overall Risk (default)
critical
90/100
CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
37.69% HIGH
38% probability -12.05%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

05 May 2008, 17:00
Published
Vulnerability first disclosed
07 Aug 2024, 07:54
Last Modified
Vulnerability information updated

Description

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 10AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 37.69% Percentile: 97%

Techniques & Countermeasures

  • CWE-131Incorrect Calculation of Buffer Size

    The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

Affected Systems

  • applemac_os_x

    < 10.5.4

  • applemac_os_x_server

    < 10.5.4

  • canonicalubuntu_linux

    6.06 | 7.04 | 7.10 | 8.04

  • fedoraprojectfedora

    8 | 9

  • UnknownPHP

    < 5.2.6

References (36)