7.5
CVSSv2

CVE-2007-1887

Published: 06/04/2007 Updated: 21/07/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 prior to 4.4.5 and PHP 5 prior to 5.2.1 allows context-dependent malicious users to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqlite_udf_decode_binary function with a 0x01 character.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

canonical ubuntu linux 7.04

canonical ubuntu linux 6.10

canonical ubuntu linux 6.06

debian debian linux 4.0

Vendor Advisories

Debian Bug report logs - #420456 php4-sqlite: sqlite_udf_decode_binary() Buffer Overflow Vulnerability Package: php4-sqlite; Maintainer for php4-sqlite is (unknown); Reported by: Sean Finney <seanius@debianorg> Date: Sun, 22 Apr 2007 12:51:01 UTC Severity: grave Tags: etch, sarge, security Found in versions php4-sqlite/1 ...
Stefan Esser discovered multiple vulnerabilities in the “Month of PHP bugs” ...
Several remote vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language, which may lead to the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1286 Stefan Esser discovered an overflow in the object reference handling code of the un ...