// For flags

CVE-2007-2872

PHP 5.1.6 - 'Chunk_Split()' Integer Overflow

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.

Los múltiples desbordamientos de enteros en la función chunk_split en PHP versión 5 anterior a 5.2.3 y PHP versión 4 anterior a 4.4.8, permiten a los atacantes remotos causar una denegación de servicio (bloqueo) o ejecutar código arbitrario por medio de los argumentos (1) chunks, (2) srclen, y (3) chunklen.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-05-29 CVE Reserved
  • 2007-05-31 First Exploit
  • 2007-06-04 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-189: Numeric Errors
  • CWE-190: Integer Overflow or Wraparound
CAPEC
References (61)
URL Date SRC
http://www.php.net/releases/5_2_3.php 2023-02-13
URL Date SRC
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795 2023-02-13
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501 2023-02-13
http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html 2023-02-13
http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html 2023-02-13
http://rhn.redhat.com/errata/RHSA-2007-0889.html 2023-02-13
http://secunia.com/advisories/25456 2023-02-13
http://secunia.com/advisories/25535 2023-02-13
http://secunia.com/advisories/26048 2023-02-13
http://secunia.com/advisories/26231 2023-02-13
http://secunia.com/advisories/26838 2023-02-13
http://secunia.com/advisories/26871 2023-02-13
http://secunia.com/advisories/26895 2023-02-13
http://secunia.com/advisories/26930 2023-02-13
http://secunia.com/advisories/26967 2023-02-13
http://secunia.com/advisories/27037 2023-02-13
http://secunia.com/advisories/27102 2023-02-13
http://secunia.com/advisories/27110 2023-02-13
http://secunia.com/advisories/27351 2023-02-13
http://secunia.com/advisories/27377 2023-02-13
http://secunia.com/advisories/27545 2023-02-13
http://secunia.com/advisories/27864 2023-02-13
http://secunia.com/advisories/28318 2023-02-13
http://secunia.com/advisories/28658 2023-02-13
http://secunia.com/advisories/30040 2023-02-13
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.482863 2023-02-13
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.335136 2023-02-13
http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml 2023-02-13
http://www.mandriva.com/security/advisories?name=MDKSA-2007:187 2023-02-13
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.020.html 2023-02-13
http://www.redhat.com/support/errata/RHSA-2007-0888.html 2023-02-13
http://www.redhat.com/support/errata/RHSA-2007-0890.html 2023-02-13
http://www.redhat.com/support/errata/RHSA-2007-0891.html 2023-02-13
http://www.securityfocus.com/archive/1/491693/100/0/threaded 2023-02-13
http://www.trustix.org/errata/2007/0023 2023-02-13
http://www.ubuntu.com/usn/usn-549-2 2023-02-13
https://usn.ubuntu.com/549-1 2023-02-13
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.html 2023-02-13
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html 2023-02-13
https://access.redhat.com/security/cve/CVE-2007-2872 2007-10-25
https://bugzilla.redhat.com/show_bug.cgi?id=242032 2007-10-25
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
<= 4.4.7
Search vendor "Php" for product "Php" and version " <= 4.4.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.1
Search vendor "Php" for product "Php" and version "5.0.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.2
Search vendor "Php" for product "Php" and version "5.0.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.3
Search vendor "Php" for product "Php" and version "5.0.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.4
Search vendor "Php" for product "Php" and version "5.0.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.5
Search vendor "Php" for product "Php" and version "5.0.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.0
Search vendor "Php" for product "Php" and version "5.1.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.1
Search vendor "Php" for product "Php" and version "5.1.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.2
Search vendor "Php" for product "Php" and version "5.1.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.3
Search vendor "Php" for product "Php" and version "5.1.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.4
Search vendor "Php" for product "Php" and version "5.1.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.5
Search vendor "Php" for product "Php" and version "5.1.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.6
Search vendor "Php" for product "Php" and version "5.1.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.0
Search vendor "Php" for product "Php" and version "5.2.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.1
Search vendor "Php" for product "Php" and version "5.2.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.2
Search vendor "Php" for product "Php" and version "5.2.2"
-
Affected