// For flags

CVE-2007-2872

PHP 5.1.6 - 'Chunk_Split()' Integer Overflow

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.

Los múltiples desbordamientos de enteros en la función chunk_split en PHP versión 5 anterior a 5.2.3 y PHP versión 4 anterior a 4.4.8, permiten a los atacantes remotos causar una denegación de servicio (bloqueo) o ejecutar código arbitrario por medio de los argumentos (1) chunks, (2) srclen, y (3) chunklen.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-05-29 CVE Reserved
  • 2007-05-31 First Exploit
  • 2007-06-04 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-09-07 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-189: Numeric Errors
  • CWE-190: Integer Overflow or Wraparound
CAPEC
References (61)
URL Date SRC
http://www.php.net/releases/5_2_3.php 2023-02-13
URL Date SRC
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795 2023-02-13
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501 2023-02-13
http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html 2023-02-13
http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html 2023-02-13
http://rhn.redhat.com/errata/RHSA-2007-0889.html 2023-02-13
http://secunia.com/advisories/25456 2023-02-13
http://secunia.com/advisories/25535 2023-02-13
http://secunia.com/advisories/26048 2023-02-13
http://secunia.com/advisories/26231 2023-02-13
http://secunia.com/advisories/26838 2023-02-13
http://secunia.com/advisories/26871 2023-02-13
http://secunia.com/advisories/26895 2023-02-13
http://secunia.com/advisories/26930 2023-02-13
http://secunia.com/advisories/26967 2023-02-13
http://secunia.com/advisories/27037 2023-02-13
http://secunia.com/advisories/27102 2023-02-13
http://secunia.com/advisories/27110 2023-02-13
http://secunia.com/advisories/27351 2023-02-13
http://secunia.com/advisories/27377 2023-02-13
http://secunia.com/advisories/27545 2023-02-13
http://secunia.com/advisories/27864 2023-02-13
http://secunia.com/advisories/28318 2023-02-13
http://secunia.com/advisories/28658 2023-02-13
http://secunia.com/advisories/30040 2023-02-13
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.482863 2023-02-13
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.335136 2023-02-13
http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml 2023-02-13
http://www.mandriva.com/security/advisories?name=MDKSA-2007:187 2023-02-13
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.020.html 2023-02-13
http://www.redhat.com/support/errata/RHSA-2007-0888.html 2023-02-13
http://www.redhat.com/support/errata/RHSA-2007-0890.html 2023-02-13
http://www.redhat.com/support/errata/RHSA-2007-0891.html 2023-02-13
http://www.securityfocus.com/archive/1/491693/100/0/threaded 2023-02-13
http://www.trustix.org/errata/2007/0023 2023-02-13
http://www.ubuntu.com/usn/usn-549-2 2023-02-13
https://usn.ubuntu.com/549-1 2023-02-13
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.html 2023-02-13
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html 2023-02-13
https://access.redhat.com/security/cve/CVE-2007-2872 2007-10-25
https://bugzilla.redhat.com/show_bug.cgi?id=242032 2007-10-25
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
<= 4.4.7
Search vendor "Php" for product "Php" and version " <= 4.4.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.1
Search vendor "Php" for product "Php" and version "5.0.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.2
Search vendor "Php" for product "Php" and version "5.0.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.3
Search vendor "Php" for product "Php" and version "5.0.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.4
Search vendor "Php" for product "Php" and version "5.0.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.5
Search vendor "Php" for product "Php" and version "5.0.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.0
Search vendor "Php" for product "Php" and version "5.1.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.1
Search vendor "Php" for product "Php" and version "5.1.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.2
Search vendor "Php" for product "Php" and version "5.1.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.3
Search vendor "Php" for product "Php" and version "5.1.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.4
Search vendor "Php" for product "Php" and version "5.1.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.5
Search vendor "Php" for product "Php" and version "5.1.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.6
Search vendor "Php" for product "Php" and version "5.1.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.0
Search vendor "Php" for product "Php" and version "5.2.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.1
Search vendor "Php" for product "Php" and version "5.2.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.2
Search vendor "Php" for product "Php" and version "5.2.2"
-
Affected