5
CVSSv2

CVE-2008-2829

Published: 23/06/2008 Updated: 09/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.

Vulnerable Product Search on Vulmon Subscribe to Product

php php

php php 5.2.6

php php 5.2.5

canonical ubuntu linux 6.06

canonical ubuntu linux 8.04

canonical ubuntu linux 7.10

canonical ubuntu linux 7.04

Vendor Advisories

It was discovered that PHP did not properly check the length of the string parameter to the fnmatch function An attacker could cause a denial of service in the PHP interpreter if a script passed untrusted input to the fnmatch function (CVE-2007-4782) ...