// For flags

CVE-2006-4020

PHP 4.4.3/5.1.4 - 'sscanf' Local Buffer Overflow

Severity Score

4.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code via a sscanf PHP function call that performs argument swapping, which increments an index past the end of an array and triggers a buffer over-read.

scanf.c en PHP 5.1.4 y anteriores, y 4.4.3 y anteriores, permite a atacantes (locales o remotos dependiendo del contexto) ejecutar código de su elección mediante una llamada a la función sscanf de PHP que realiza un intercambio de argumentos que incrementa un índice más allá del final de un array y dispara una lectura de búfer fuera de límite.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-08-08 CVE Reserved
  • 2006-08-08 CVE Published
  • 2006-08-16 First Exploit
  • 2023-11-12 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
References (42)
URL Tag Source
http://secunia.com/advisories/21403 Third Party Advisory
http://secunia.com/advisories/21467 Third Party Advisory
http://secunia.com/advisories/21546 Third Party Advisory
http://secunia.com/advisories/21608 Third Party Advisory
http://secunia.com/advisories/21683 Third Party Advisory
http://secunia.com/advisories/21768 Third Party Advisory
http://secunia.com/advisories/21847 Third Party Advisory
http://secunia.com/advisories/22004 Third Party Advisory
http://secunia.com/advisories/22039 Third Party Advisory
http://secunia.com/advisories/22069 Third Party Advisory
http://secunia.com/advisories/22440 Third Party Advisory
http://secunia.com/advisories/22487 Third Party Advisory
http://secunia.com/advisories/22538 Third Party Advisory
http://secunia.com/advisories/23247 Third Party Advisory
http://securityreason.com/securityalert/1341 Third Party Advisory
http://securitytracker.com/id?1016984 Vdb Entry
http://support.avaya.com/elmodocs2/security/ASA-2006-221.htm X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-222.htm X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-223.htm X_refsource_confirm
http://www.php.net/ChangeLog-5.php#5.1.5 X_refsource_confirm
http://www.php.net/release_5_1_5.php X_refsource_confirm
http://www.securityfocus.com/bid/19415 Vdb Entry
http://www.vupen.com/english/advisories/2006/3193 Vdb Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11062 Signature
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
beta_4_patch1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
beta1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
beta2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
beta3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
beta4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
rc2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.0
Search vendor "Php" for product "Php" and version "4.0.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.1
Search vendor "Php" for product "Php" and version "4.0.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.1
Search vendor "Php" for product "Php" and version "4.0.1"
patch1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.1
Search vendor "Php" for product "Php" and version "4.0.1"
patch2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.2
Search vendor "Php" for product "Php" and version "4.0.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.3
Search vendor "Php" for product "Php" and version "4.0.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.3
Search vendor "Php" for product "Php" and version "4.0.3"
patch1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.4
Search vendor "Php" for product "Php" and version "4.0.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.4
Search vendor "Php" for product "Php" and version "4.0.4"
patch1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.5
Search vendor "Php" for product "Php" and version "4.0.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.6
Search vendor "Php" for product "Php" and version "4.0.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.7
Search vendor "Php" for product "Php" and version "4.0.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.7
Search vendor "Php" for product "Php" and version "4.0.7"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.7
Search vendor "Php" for product "Php" and version "4.0.7"
rc2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.7
Search vendor "Php" for product "Php" and version "4.0.7"
rc3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.1.0
Search vendor "Php" for product "Php" and version "4.1.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.1.1
Search vendor "Php" for product "Php" and version "4.1.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.1.2
Search vendor "Php" for product "Php" and version "4.1.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.2
Search vendor "Php" for product "Php" and version "4.2"
dev
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.2.0
Search vendor "Php" for product "Php" and version "4.2.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.2.1
Search vendor "Php" for product "Php" and version "4.2.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.2.2
Search vendor "Php" for product "Php" and version "4.2.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.2.3
Search vendor "Php" for product "Php" and version "4.2.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.0
Search vendor "Php" for product "Php" and version "4.3.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.1
Search vendor "Php" for product "Php" and version "4.3.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.2
Search vendor "Php" for product "Php" and version "4.3.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.3
Search vendor "Php" for product "Php" and version "4.3.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.4
Search vendor "Php" for product "Php" and version "4.3.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.5
Search vendor "Php" for product "Php" and version "4.3.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.6
Search vendor "Php" for product "Php" and version "4.3.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.7
Search vendor "Php" for product "Php" and version "4.3.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.8
Search vendor "Php" for product "Php" and version "4.3.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.9
Search vendor "Php" for product "Php" and version "4.3.9"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.10
Search vendor "Php" for product "Php" and version "4.3.10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.11
Search vendor "Php" for product "Php" and version "4.3.11"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.0
Search vendor "Php" for product "Php" and version "4.4.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.1
Search vendor "Php" for product "Php" and version "4.4.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.2
Search vendor "Php" for product "Php" and version "4.4.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.3
Search vendor "Php" for product "Php" and version "4.4.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0
Search vendor "Php" for product "Php" and version "5.0"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0
Search vendor "Php" for product "Php" and version "5.0"
rc2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0
Search vendor "Php" for product "Php" and version "5.0"
rc3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
rc2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
rc3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.1
Search vendor "Php" for product "Php" and version "5.0.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.2
Search vendor "Php" for product "Php" and version "5.0.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.3
Search vendor "Php" for product "Php" and version "5.0.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.4
Search vendor "Php" for product "Php" and version "5.0.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.5
Search vendor "Php" for product "Php" and version "5.0.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.0
Search vendor "Php" for product "Php" and version "5.1.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.1
Search vendor "Php" for product "Php" and version "5.1.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.2
Search vendor "Php" for product "Php" and version "5.1.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.4
Search vendor "Php" for product "Php" and version "5.1.4"
-
Affected