CVE-2007-4840
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode_headers, (3) iconv_mime_decode, or (4) iconv_strlen function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.
PHP 5.2.4 y anteriores permite a usuarios locales o remotos dependiendo del contexto provocar una denegación de serviciO (caída de aplicación) mediante (1) una cadena larga en el parámetro out_charset para la función iconf; o una cadena larga en el parámetro charset para las funciones (2) iconv_mime_decode_headers, (3) iconv_mime_decode, o (4) iconf_strlen. NOTA: esto no podrían ser una vulnerabilidad en la mayoría de los entornos de servidor web que soportan múltiples hilos, a no ser que se pueda demostrar que estos problemas permiten ejecución de código.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-09-12 CVE Reserved
- 2007-09-12 CVE Published
- 2024-07-16 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://osvdb.org/38916 | Vdb Entry | |
http://secunia.com/advisories/27102 | Third Party Advisory | |
http://secunia.com/advisories/27659 | Third Party Advisory | |
http://secunia.com/advisories/28658 | Third Party Advisory | |
http://secunia.com/advisories/30040 | Third Party Advisory | |
http://securityreason.com/securityalert/3122 | Third Party Advisory | |
http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0242 | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/478730/100/0/threaded | Mailing List | |
https://issues.rpath.com/browse/RPL-1943 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html | 2018-10-15 | |
http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml | 2018-10-15 | |
http://www.securityfocus.com/archive/1/491693/100/0/threaded | 2018-10-15 |