CVE-2007-3806
PHP 5.2.3 - 'glob()' Denial of Service
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The glob function in PHP 5.2.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter, probably related to memory corruption or an invalid read on win32 platforms, and possibly related to lack of initialization for a glob structure.
La función glob en PHP versión 5.2.3, permite a atacantes dependiendo del contexto causar una denegación de servicio y posiblemente ejecutar código arbitrario por medio de un valor no válido del parámetro flags, probablemente relacionado con la corrupción de memoria o una lectura no válida en plataformas win32, y posiblemente relacionado con la falta de inicialización para una estructura glob.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-07-14 First Exploit
- 2007-07-16 CVE Reserved
- 2007-07-17 CVE Published
- 2024-08-07 CVE Updated
- 2024-10-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
- CWE-399: Resource Management Errors
CAPEC
References (19)
URL | Tag | Source |
---|---|---|
http://cvs.php.net/viewvc.cgi/php-src/ext/standard/dir.c?r1=1.166&r2=1.167 | X_refsource_misc | |
http://cvs.php.net/viewvc.cgi/php-src/ext/standard/dir.c?view=log | X_refsource_misc | |
http://osvdb.org/36085 | Vdb Entry | |
http://www.php.net/ChangeLog-5.php#5.2.4 | X_refsource_confirm | |
http://www.php.net/releases/5_2_4.php | X_refsource_confirm | |
http://www.securityfocus.com/bid/24922 | Vdb Entry | |
http://www.securityfocus.com/bid/25498 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35437 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/4181 | 2007-07-14 | |
http://www.exploit-db.com/exploits/4181 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/26085 | 2017-09-29 | |
http://secunia.com/advisories/26642 | 2017-09-29 | |
http://secunia.com/advisories/27102 | 2017-09-29 | |
http://secunia.com/advisories/30158 | 2017-09-29 | |
http://secunia.com/advisories/30288 | 2017-09-29 | |
http://www.debian.org/security/2008/dsa-1572 | 2017-09-29 | |
http://www.debian.org/security/2008/dsa-1578 | 2017-09-29 | |
http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml | 2017-09-29 | |
http://www.vupen.com/english/advisories/2007/2547 | 2017-09-29 |