security flaw
Published Dec 8, 2004
10.0
HIGHCVSS 2.0
EPSS 16.16%
Description
Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
Affected products
No data.
Configuration 2
- 4.10
No data.
Red Hat Enterprise Linux 3
php-0:4.3.2-19.ent
Fixed · RHSA-2004:687
Red Hat Enterprise Linux 4
php-0:4.3.9-3.2
Fixed · RHSA-2005:032
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
n/a
Fixed · RHSA-2005:031
Red Hat Enterprise Linux ES version 2.1
n/a
Fixed · RHSA-2005:031
Red Hat Enterprise Linux WS version 2.1
n/a
Fixed · RHSA-2005:031
Red Hat Linux Advanced Workstation 2.1
n/a
Fixed · RHSA-2005:031
Red Hat Stronghold 4
n/a
Fixed · RHSA-2005:882
Stronghold 4.0 for Red Hat Enterprise Linux AS (version 2.1)
n/a
Fixed · RHSA-2005:816
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | php-0:4.3.2-19.ent | Fixed | RHSA-2004:687 |
| Red Hat Enterprise Linux 4 | php-0:4.3.9-3.2 | Fixed | RHSA-2005:032 |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | n/a | Fixed | RHSA-2005:031 |
| Red Hat Enterprise Linux ES version 2.1 | n/a | Fixed | RHSA-2005:031 |
| Red Hat Enterprise Linux WS version 2.1 | n/a | Fixed | RHSA-2005:031 |
| Red Hat Linux Advanced Workstation 2.1 | n/a | Fixed | RHSA-2005:031 |
| Red Hat Stronghold 4 | n/a | Fixed | RHSA-2005:882 |
| Stronghold 4.0 for Red Hat Enterprise Linux AS (version 2.1) | n/a | Fixed | RHSA-2005:816 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 16.16% (0.16160) | 96.84th | v5 (v2026.06.15) |
| Jun 15, 2026 | 16.16% (0.16160) | 96.51th | v5 (v2026.06.15) |
| Dec 28, 2025 | 24.19% (0.24190) | 95.88th | v4 (v2025.03.14) |
| Dec 27, 2025 | 36.63% (0.36629) | 97.00th | v4 (v2025.03.14) |
| Oct 28, 2025 | 24.19% (0.24190) | 95.82th | v4 (v2025.03.14) |
| Oct 27, 2025 | 36.63% (0.36629) | 96.95th | v4 (v2025.03.14) |
| Oct 1, 2025 | 24.19% (0.24190) | 95.91th | v4 (v2025.03.14) |
| Jul 30, 2025 | 36.63% (0.36629) | 96.98th | v4 (v2025.03.14) |
| Mar 30, 2025 | 24.19% (0.24190) | 95.61th | v4 (v2025.03.14) |
| Mar 29, 2025 | 40.78% (0.40782) | 96.06th | v4 (v2025.03.14) |
| Mar 17, 2025 | 24.19% (0.24190) | 95.61th | v4 (v2025.03.14) |
| Dec 17, 2024 | 2.35% (0.02355) | 89.49th | v3 (v2023.03.01) |
| Jul 10, 2024 | 0.87% (0.00874) | 82.58th | v3 (v2023.03.01) |
| Nov 15, 2023 | 0.87% (0.00874) | 80.56th | v3 (v2023.03.01) |
| Mar 30, 2023 | 0.94% (0.00944) | 80.80th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.99% (0.00986) | 81.17th | v3 (v2023.03.01) |
| Mar 6, 2023 | 23.22% (0.23224) | 96.69th | v2 (v2022.01.01) |
| Feb 23, 2023 | 23.22% (0.23224) | 96.68th | v2 (v2022.01.01) |
| Feb 4, 2022 | 23.22% (0.23224) | 94.68th | v2 (v2022.01.01) |
No CWE recorded.
References (19)
- http://marc.info/?l=bugtraq&m=110314318531298&w=2 mailing-listx_refsource_BUGTRAQIssue TrackingThird Party Advisory
- http://www.hardened-php.net/advisories/012004.txt x_refsource_MISCThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:151 vendor-advisoryx_refsource_MANDRAKEThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:072 vendor-advisoryx_refsource_MANDRAKEThird Party Advisory
- http://www.osvdb.org/12411 vdb-entryx_refsource_OSVDBBroken Link
- http://www.php.net/release_4_3_10.php x_refsource_CONFIRMRelease NotesVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-032.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2005-816.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/advisories/9028 vendor-advisoryx_refsource_HPThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/384920 mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/12045 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2004-1018 Vendor Advisory
- https://bugzilla.fedora.us/show_bug.cgi?id=2344 vendor-advisoryx_refsource_FEDORABroken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=1617352 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18515 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2004-1018
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10949 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2004-1018
- https://www.ubuntu.com/usn/usn-99-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
Change history (0)
No recorded changes yet.