7.5
CVSSv2

CVE-2007-1777

Published: 30/03/2007 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the zip_read_entry function in PHP 4 prior to 4.4.5 allows remote malicious users to execute arbitrary code via a ZIP archive that contains an entry with a length value of 0xffffffff, which is incremented before use in an emalloc call, triggering a heap overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 3.0.1

php php 3.0.10

php php 3.0.18

php php 3.0.2

php php 3.0.9

php php 4.0.0

php php 4.0.4

php php 4.1.1

php php 4.1.2

php php 4.3.1

php php 4.3.10

php php 4.3.7

php php 4.3.8

php php 3.0.11

php php 3.0.12

php php 3.0.3

php php 3.0.4

php php 4.0.1

php php 4.0.5

php php 4.0.6

php php 4.2.0

php php 4.2.1

php php 4.3.11

php php 4.3.2

php php 4.3.9

php php 4.4.0

php php 4.4.1

php php 3.0

php php 3.0.15

php php 3.0.16

php php 3.0.17

php php 3.0.7

php php 3.0.8

php php 4.0.3

php php 4.0.7

php php 4.1.0

php php 4.2

php php 4.3.0

php php 4.3.5

php php 4.3.6

php php 4.4.4

php php 3.0.13

php php 3.0.14

php php 3.0.5

php php 3.0.6

php php 4.0.2

php php 4.2.2

php php 4.2.3

php php 4.3.3

php php 4.3.4

php php 4.4.2

php php 4.4.3

Vendor Advisories

Several remote vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language, which may lead to the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1286 Stefan Esser discovered an overflow in the object reference handling code of the un ...
Several remote vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language, which may lead to the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1286 Stefan Esser discovered an overflow in the object reference handling code of the un ...

Exploits

source: wwwsecurityfocuscom/bid/23169/info PHP is prone to an integer-overflow vulnerability because it fails to ensure that integer values aren't overrun Attackers may exploit this issue to cause a heap-based buffer overflow Exploiting this issue may allow attackers to execute arbitrary machine code in the context of the affected appl ...